Hacker wipes Romania's entire land registry - via a stolen password

22.07.2026 8
Hacker wipes Romania's entire land registry - via a stolen password

A single hacker deleted Romania's entire national land registry, freezing the country's property market. On 14 July 2026, an attacker known as ByteToBreach broke into ANCPI - the National Agency for Cadastre and Real Estate Advertising - and, after a failed extortion attempt, wiped its core database along with systems and backups. The most important detail for anyone who cares about security is how they got in: not through some exotic exploit, but with valid stolen credentials. A working login, not a broken firewall, brought a national institution to a standstill.

What happened

According to reporting from Cybernews and other security outlets, the attacker logged in with legitimate credentials, spent time on internal reconnaissance, and then tried to extort the agency. When that failed, they deleted the main registry and attempted to destroy the backups too. Romania's real-estate market ground to a halt: official applications, websites and email servers went down, and notaries could no longer authenticate property sales, register transactions or record mortgages. For a country in the middle of routine property transfers, the timing could hardly have been worse.

Not a total wipe - backups saved the day

There is a silver lining worth stating plainly, because early headlines made it sound irreversible. ANCPI says the attacker did not manage to destroy all of its data, because backups were stored in several separate locations. Recovery and rebuilding are under way. It is a textbook reminder that off-site, redundant backups are the difference between a bad week and a permanent catastrophe - the same principle that applies to your own data at home.

Who was behind it

The security firm KELA linked the ByteToBreach alias to an individual named Zakaria Mahdjoub, said to operate out of Oran, Algeria. The actor has a track record of hitting government agencies and e-government portals, including a breach of Sweden's e-government portal earlier in 2026. The stolen material reportedly included citizen data, internal documents, employee credentials and the source code for the agency's Eterra and RENNS systems.

The real lesson: credentials, not firewalls

This breach is a clear example of a pattern behind most modern attacks: they start with a working username and password, not a network intrusion. Stolen and reused credentials are the master key, which is why massive password leaks feed the next wave of breaches. It is also a useful reminder of what different tools actually do. A VPN encrypts your connection and hides your IP - genuinely important for privacy - but it does nothing if your password is stolen or reused. Account security is a separate layer: a unique password for every service, a password manager to keep track, and multi-factor authentication so a single leaked password is not enough to log in.

Conclusion: An entire country's land registry was taken down not by a sophisticated cyber-weapon but by a valid login in the wrong hands. Protect your privacy with a VPN, protect your accounts with unique passwords and multi-factor authentication, and keep real backups of anything you cannot afford to lose. The three are different jobs - and this attack shows what happens when the second one is neglected.
Tags: data breach credentials romania cybersecurity mfa

Read also