CTIPilot
← Back to Daily brief 2026-07-19
NOTABLEupdatedNATOB2incident

Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware

Romanian land-registry authority ANCPI down for days after a cyberattack; data-leak operator ByteToBreach claims theft and ransomware

Analysis

Romania's National Agency for Cadastre and Real Estate Publicity (ANCPI), the government body operating the national land-registry and cadastre platforms (the e-Terra cadastral application and RENNS) that citizens, notaries, lawyers, banks and other authorities depend on for property transactions; has had all of its IT systems, including institutional email, offline since Tuesday 14 July 2026, in what it first called a "technical incident" before confirming a cyberattack; as of 17 July the systems remained down pending investigation (Help Net Security, 2026-07-16; Public Record, 2026-07-17). A threat actor using the alias ByteToBreach posted ANCPI data for sale on a dark-web forum on 15 July, claiming to hold Romanian-citizen records and various ANCPI databases, a copied GitLab server carrying the source code for e-Terra and RENNS, and to have deployed a ransomware variant (Help Net Security, 2026-07-16); in a screenshot the attacker published, he also states he began deleting the available backups (Public Record, 2026-07-17). ANCPI states the data it administers "has not been compromised as a result of this incident", a position not yet reconciled with the attacker's claims.

KELA, which profiles ByteToBreach as a persistent data-leak operator active since June 2025, documents the actor's general initial-access tradecraft as "exploiting known vulnerabilities in cloud and corporate infrastructure, reusing stolen credentials harvested from infostealers and phishing, and at times resorting to brute force," with a victim list spanning government, banking and other sectors across multiple countries, a bank in Poland among the organizations that acknowledged their breaches (KELA Cyber, 2026-07-17). Public Record's investigation reports that ANCPI's ~1.5-million-lei framework contract for cybersecurity services required constant active services (a 24/7 call-centre, at-least-annual technical audits, and ongoing monitoring and intervention over 48 months) yet the contracted vendor's owner now characterises the firm as "just a license provider… like buying Microsoft licences on eMAG" and says he had no contractual obligation to detect an attack, a self-characterisation Public Record reports the contract's own terms directly contradict; the same reporting notes a similar December 2025 cyberattack on Romania's National Water Administration (ANAR, roughly 1,000 systems affected), an agency the same security vendors had also supplied (Public Record, 2026-07-17).

Cited evidence

They claim to have compromised data of Romanian citizens and various ANCPI databases, made a copy of the agency's GitLab servers and the source code contained within, and deployed ransomware.

ANCPI stated that the data administered through its IT systems has not been compromised as a result of this incident.

Help Net Security 2026-07-16

Exploiting known vulnerabilities in cloud and corporate infrastructure, reusing stolen credentials harvested from infostealers and phishing, and at times resorting to brute force

KELA Cyber 2026-07-17

The hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency.

Risky Business News 2026-07-20

KELA assesses the actor behind the campaign, ByteToBreach, is likely operated by Zakaria Mahdjoub, an individual based in Oran, Algeria.

KELA Cyber Intelligence Center

atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor

au compromis serverele de autentificare; au pătruns în VMware vCenter, adică sistemul care administrează întreaga infrastructură virtuală; au enumerat toate cele 1.083 de mașini virtuale; au executat mișcare laterală în rețea; au șters aproximativ 100 de mașini virtuale; au criptat servere ESXi cu ransomware

PS News (relaying the same DNSC report) 2026-07-24

infrastructura ANCPI nu beneficia de un antivirus instalat pe serverele care rulau aplicațiile principale

nu există indicii că baza de date principală Oracle Exadata ar fi fost compromisă

go4it.ro (relaying the DNSC interim technical report) 2026-07-24

Updates2

Update

The still-open ANCPI (Romanian National Agency for Cadastre and Real Estate Publicity) incident developed on two fronts. First, an impact contradiction: on 2026-07-20 ANCPI stated publicly, following completed security verification, that its technical and legal databases had not been affected (Digi24, 2026-07-20), squarely against extortion operator ByteToBreach's earlier claim, reported by Risky Business News, that the "hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency" (Risky Business News, 2026-07-20). The agency frames the multi-day e-Terra/RENNS outage (down since 14 July) as deliberate protective isolation and says it is migrating applications to the Romanian Government Cloud, coordinated by the Special Telecommunications Service, expected to complete 22 July before any phased service restoration.

Second, actor context: KELA's updated profile assesses ByteToBreach is likely a single operator based in Oran, Algeria, active since June 2025 across forums, Dread, Telegram and a storefront, with a victim set spanning government, banking, airline and university targets across several countries, and access methods documented as cloud/corporate-infrastructure exploitation, reuse of infostealer/phishing-harvested credentials, and brute force (KELA, 2026-07-17).

Update

The picture of the attack on ANCPI, Romania's national cadastre and land-registration agency, has changed substantially. Earlier coverage recorded the agency's own position that its databases were not affected. Romania's national cybersecurity directorate DNSC has since published an interim technical report, relayed with direct quotation by Romanian technology press, that supersedes that framing on the point that matters most: the attackers extracted approximately two million records concerning users of the payment platform, containing names, e-mail addresses, identifiers and password hashes, in the report's Romanian, "atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor" (PS News, 2026-07-24). The "databases not affected" assurance survives only in a much narrower form; DNSC states there is no indication the main Oracle Exadata database was compromised (go4it.ro, 2026-07-24), which is a different claim from "no data was taken", since a separate payment-platform datastore demonstrably was.

The intrusion path DNSC describes is the one that makes a virtualized government estate fail all at once. Per the report the attackers compromised the authentication servers, penetrated VMware vCenter (the system administering the entire virtual infrastructure) enumerated all 1,083 virtual machines, executed lateral movement, deleted approximately 100 virtual machines and encrypted ESXi servers with ransomware (PS News, 2026-07-24). Identity compromise first, then the virtualization control plane, then destruction at the hypervisor layer beneath every guest operating system, the per-VM security stack never gets a vote. Source code for the eTerra, GIS, ePayment and security modules was taken from the agency's GitLab as well. DNSC's account of why it worked is unusually blunt for a national authority; the ANCPI infrastructure had no antivirus installed on the servers running its main applications (go4it.ro, 2026-07-24), alongside known unpatched vulnerabilities and a web-application firewall retaining connection logs for only seven minutes, which is also why the forensic picture is partial. DNSC's director had already assessed on 2026-07-18 that the attack exploited already-known vulnerabilities and could have been prevented (go4it.ro, 2026-07-18).

Triage: in vCenter and ESXi audit telemetry, the discriminating sequence is not any single administrative action but the ordering, an authentication from an unusual source or service account, followed by a full inventory enumeration of virtual machines, followed by power-off or delete operations across guests that share no application grouping. Routine administration enumerates inventory constantly and backup tooling touches many VMs, so volume alone is noise; the signal is enumeration by a principal that does not normally perform it, immediately followed by destructive operations spanning unrelated workloads.

Sources8

Revision history

  1. Published 2026-07-19T0408Z-intel
  2. Update 2026-07-21T0409Z-intel

    Update on the ANCPI (Romanian National Agency for Cadastre) cyberattack: on 2026-07-20 the agency stated, after security verification, that its technical and legal databases "have not been affected", directly contradicting data-leak operator ByteToBreach's claim of deleting backups after a failed extortion. ANCPI is migrating its applications to the Romanian Government Cloud, expected to finish 22 July, before any phased service restoration. KELA separately profiled the ByteToBreach operator; the contradiction between the wipe claim and the "databases intact" statement is itself the notable fact; both are held, neither is resolved.

    Changed: evidence sources tags techniques body

  3. Update 2026-07-26T1308Z-audit

    Romania's national cybersecurity directorate DNSC published an interim technical report on the ANCPI national land-registry attack that materially supersedes the agency's earlier "databases not affected" assurance. DNSC describes compromise of the authentication servers, entry into VMware vCenter, enumeration of all 1,083 virtual machines, deletion of roughly 100 of them and ransomware encryption of ESXi hosts, plus exfiltration of approximately two million ePayment platform user records (names, e-mail addresses, identifiers and password hashes). The "core database intact" claim survives only for the Oracle Exadata database specifically.

    Changed: affected_products evidence sources techniques body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.