2026-07-29 · view entry permalink →
Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to it
The university's press release is specific about process and silent about substance. It states that a cyberattack was recently identified which affected the institution's IT infrastructure and the functioning of digital services used in academic and administrative activity, that the competent authorities were notified immediately — naming DNSC, the national cybersecurity directorate; ANSPDCP, the data-protection authority; and DIICOT, the organised-crime and terrorism prosecution directorate — and that technical teams are working with specialists on the gradual resumption of affected services (Aradon.ro, 2026-07-28). Radio România is direct about the gaps: the university has not specified which systems are unavailable, nor whether personal data was compromised or extracted, and authorities are yet to determine the nature of the attack, how the attackers entered the systems and the scope of any damage, with no timeframe announced for full restoration (Radio România, 2026-07-28). The notification of all three authorities at once is itself informative: DIICOT's involvement indicates a criminal referral, and ANSPDCP's indicates the university considered a personal-data breach at least possible, even while declining to confirm one.
The actor question should be read carefully, because the two available pieces of information do not actually touch. The Qilin ransomware operation listed the university on its leak site with an estimated attack date of 2026-07-26, two days before the university's disclosure (Ransomware.live, 2026-07-26). That listing is the only source for the connection: it carries no description text, and none of the Romanian outlets covering the incident — including the national broadcaster — mentions Qilin, ransomware, or any actor at all. So while the timing is consistent with an unresolved extortion negotiation, which is the ordinary explanation for a victim confirming a "cybersecurity incident" without naming a cause, nothing in the university's statement corroborates the claim, and treating the two as one confirmed story would be assembling an attribution the sources do not make.
recent a fost identificat un atac cibernetic care a afectat infrastructura informatică a universității
Universitatea nu a precizat, deocamdată, care sunt sistemele indisponibile și nici dacă au fost compromise sau extrase date personale.
Autoritățile urmează să stabilească natura atacului, modul în care agresorii au pătruns în sistemele informatice și amploarea eventualelor prejudicii.