ctipilot.ch

Hungarian State Treasury (MVH) breach

incident · incident:hungary-treasury-mvh-bytetobreach-2026-08

Late-July 2026 intrusion into Hungary's Magyar Államkincstár (State Treasury), specifically its Agricultural and Rural Development Office (MVH), attributed by Hungarian reporting to the actor ByteToBreach. Cybersecurity experts consulted by Telex.hu on attacker-leaked screenshots describe entry through an unpatched Oracle WebLogic Server carrying fixes from an October 2017 patch cycle, escalation to Windows domain-administrator privileges across a reported 116 virtual machines, and ransomware encryption of employee workstation files; Treasury officials state citizen data was unaffected (Telex.hu, 2026-08-03; Risky Bulletin, 2026-08-05).

Aliases: Magyar Államkincstár kibertámadás, MVH breach

Coverage timeline
1
first 2026-08-05 → last 2026-08-05
Peak priority
high
1 high
Sources cited
4
3 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Related entities below
ATT&CK techniques
3
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
Oracle WebLogic Server

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Persistence TA0003

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Privilege Escalation TA0004

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Stealth TA0005

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic · ATT&CK page ↗

Story timeline

  1. 2026-08-05ByteToBreach hits Hungary's State Treasury after Romania's land registry — the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle
    active-threatsThe actor who wiped Romania's cadastre reaches a second EU government body through legacy WebLogic

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed to

related to

Where this entity is cited

  • active-threats1

Source distribution

  • telex.hu2 (50%)
  • kelacyber.com1 (25%)
  • news.risky.biz1 (25%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Hungarian State Treasury (MVH) breach (1)

2026-08-05 · view entry permalink →

HIGHNATOB2

ByteToBreach hits Hungary's State Treasury after Romania's land registry — the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle

Hungarian outlet Telex.hu reports that the Magyar Államkincstár — Hungary's State Treasury — was breached in late July 2026, with the intrusion confirmed by Treasury officials to Hungarian journalists over the weekend of 2026-08-01/02, and specifically affecting its Agricultural and Rural Development Office (MVH) (Telex.hu, 2026-08-03). Risky Bulletin frames the significance plainly: the same actor who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system (Risky Bulletin, 2026-08-05). That is the part which matters beyond Hungary — this is one financially-motivated operator, assessed by KELA as likely an individual, reaching two national government bodies of two EU member states inside roughly a month (KELA, 2026-07-17).

The reported entry point is the transferable part, and it is not a novel technique. Per cybersecurity experts Telex.hu consulted, who reviewed screenshots the attacker leaked, access came through an unpatched Oracle WebLogic Server, with the outlet linking to Oracle's October 2017 Critical Patch Update (Telex.hu, 2026-08-03). No source names a specific CVE, so none is recorded in this entry's metadata and none should be inferred from the patch-cycle reference. What the reporting does support is the shape: a public application server carrying fixes that shipped roughly nine years ago, still reachable, still in service at a national treasury.

From that foothold the attacker escalated to domain-administrator rights — Telex.hu's sources state the attackers obtained the highest-level administrative privileges in practically every critical system — and the same reporting puts the reach at 116 virtual machines and 229 TB of data, with ransomware encrypting files on employee workstations (Telex.hu, 2026-08-03). Those scope figures derive from the experts' reading of attacker-supplied screenshots rather than from an official statement, and should be held as a claim under review. Treasury officials state that customer and citizen data was not affected. On origin the two accounts diverge: Telex.hu reports the Treasury's own experts attributing the attack to Russian servers, while ByteToBreach disputes that characterisation, denies making a ransom demand and describes the motive as financial. Neither account is independently confirmed. Hungary's National Cybersecurity Institute is investigating and the affected servers were disconnected on discovery.

Triage: exploitation of a legacy application server looks in telemetry like the application server's own service account doing something new — a Java process spawning a command interpreter, outbound connections from a host that should only receive them, or an authentication from the server's account to a system it has never touched. On a host that has run unchanged for years, a first-of-its-kind child process or destination is a stronger signal than it would be anywhere else, precisely because the baseline is so static.

The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.

Risky Bulletin (Risky Business Media) 2026-08-05

A támadók gyakorlatilag minden kritikus rendszerben megszerezték a legmagasabb szintű rendszergazdai jogosultságokat

Telex.hu 2026-08-03

Builds on: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · 2026-07-26/ancpi-romania-dnsc-report-2m-epayment-records-exfiltrated

incident05 Aug 04:12Zmulti-sourceOpen finding ↗