Lithuania's Centre of Registers loses ~600,000 state-register records to abused institutional credentials; foreign-state actor suspected
Lithuania's Prosecutor General's Office disclosed that attackers accessed more than 600,000 records from the Centre of Registers — the state enterprise that manages the Real Estate Register and the Register of Legal Entities — over a window running from early April to disclosure (The Record, 2026-05-26). The access vector was not a software exploit but credential abuse: attackers obtained and misused login credentials assigned to institutions authorised to query the registers, originating the connections from foreign-administered infrastructure (The Record, 2026-05-26). Exfiltrated fields include names, dates of birth, national ID numbers, property addresses, cadastral numbers and registry identifiers; contact details, bank accounts and payment data were reported as not in the stolen set. Lithuanian officials publicly framed the incident as likely the work of a foreign country, with one politician alleging Russian-intelligence hallmarks, and the head of the Centre of Registers resigned within days (Euronews, 2026-05-25; LRT, 2026-05-22). Reporting cross-references comparable intrusions against Slovakia's land register and Ukraine's state registers.
Why it matters to us: property and corporate-entity registers are high dossier-value targets — they let an intelligence service resolve home addresses and asset holdings for officials, diplomats and military personnel — and the identical register-API architecture is in production across every EU member state, Switzerland's commercial register (Zefix) and cantonal land registries included. The kill chain here is authorised-account abuse (T1078 Valid Accounts / T1530 Data from Cloud Storage), not a CVE: institutional service accounts querying register APIs need per-institution rate limits, MFA on the service principal, ASN/IP-range anchoring (institutional access should originate from known networks), and query-volume anomaly detection. Hunt for bulk-query bursts from institutional accounts outside business hours or from ASNs inconsistent with the institution's historical access pattern, and retain register access logs long enough to reconstruct a multi-week exfiltration window.
ATT&CK mapping
2 techniques mapped from the cited reporting · MITRE ATT&CK v19.1
Initial Access TA0001
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Persistence TA0003
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Privilege Escalation TA0004
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Stealth TA0005
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Collection TA0009
T1530Data from Cloud Storage
Adversaries may access data from cloud storage.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.