Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Romania map glowing silhouette outline made of stars lines dots triangles, low polygonal shapes.

Cyberattack on Romania’s Land Registry Highlights Risk to Critical Public Registers

Romania’s National Agency for Cadastre and Land Registration — ANCPI (Agenția Națională de Cadastru și Publicitate Imobiliară) — confirmed a cyberattack that caused a serious disruption to its IT systems. Affected services included e-Terra, the cadastre and land registry system, as well as the agency’s email services.

The incident matters because it shows how disruption to a public register can have a direct effect on the real economy. When cadastre and land registration services are unavailable, notaries, citizens, institutions and businesses may be temporarily blocked from completing property transactions, certificates and administrative processes.

ANCPI’s official position is that the technical and legal databases were not affected. At the same time, unconfirmed claims have circulated publicly about a potentially wider impact, including deleted systems and attempted extortion. As of the latest public information, those claims have not been confirmed by official Romanian institutions.

What Is Confirmed

ANCPI confirmed that it was targeted by a cyberattack that made the agency’s managed IT systems unavailable. These included e-Terra, email services and other internal applications.

The agency described the incident as one of the most serious technical disruptions in its history. Services were temporarily stopped while teams worked on restoration, verification and infrastructure hardening.

According to official information:

  • ANCPI systems became unavailable after the attack;
  • e-Terra was among the affected services;
  • technical teams and cybersecurity specialists are working on recovery;
  • infrastructure is being reinstalled, verified and hardened;
  • applications are being migrated to Government Cloud;
  • ANCPI states that technical and legal databases were not affected;
  • the agency says it had backup locations for recovery.

At this stage, the incident should therefore be described as a confirmed service disruption and infrastructure recovery effort, not as an officially confirmed loss of the entire land registry database.

What Remains Unconfirmed

Several media and security reports cite claims that the attacker accessed internal systems, source code, credentials and data, and after a failed extortion attempt deleted systems or backups.

These claims matter because they describe a potentially more serious scenario. However, they should currently be treated as unconfirmed information unless supported by official technical details, a forensic report or publicly verifiable evidence.

The correct framing is:

  • the cyberattack is confirmed;
  • the disruption to ANCPI services is confirmed;
  • e-Terra was affected as a service;
  • official statements say core technical and legal databases were not affected;
  • claims about full database deletion, mass compromise of land registry records or destroyed backups remain unconfirmed.

This distinction matters. In public registers, inaccurate communication can increase distrust, create panic and complicate the work of institutions and professional groups that depend on the service.

Why This Matters

Cadastre and land registries are critical public services. They are not only administrative databases. They support legal certainty, property transactions, notarial processes, bank valuations, investment decisions, construction procedures and citizen services.

When such a system stops, the impact does not remain in the IT department. It extends to:

  • notaries;
  • citizens;
  • banks;
  • construction companies;
  • real estate agencies;
  • municipalities;
  • investors;
  • legal and administrative processes;
  • government services that depend on registry checks.

This is the practical link to operational resilience. Even when data loss is not confirmed, lack of access to the data can temporarily block a whole service or market process.

Link to NIS2 and Public Service Resilience

The ANCPI incident reflects the direction of European regulation. NIS2 (Network and Information Security Directive) places stronger focus on risk management, incident reporting, service continuity, supplier governance and technical security measures.

For public institutions and operators of critical digital services, this means cybersecurity can no longer be treated as a separate technical cost. It is part of the service’s ability to operate, recover and maintain public trust.

The key lessons are clear:

  • public registers need verifiable backup and restore processes;
  • backups must be isolated and regularly tested;
  • access to critical systems must be restricted and monitored;
  • credentials must be managed as high-risk assets;
  • patching and vulnerability management must be continuous;
  • logs must be collected centrally;
  • institutions need a ready incident response plan;
  • communication must separate confirmed facts from unconfirmed claims.

This incident is directly connected to the topic of operational resilience. For critical public registers, resilience does not end with having backups or a recovery plan documented on paper. The key question is whether the organization can demonstrably restore the service in a realistic scenario, with clear priorities, dependencies, roles, and communication. This is why Disaster Recovery (DR) testing is a critical part of operational resilience. If the restore process has never been tested under conditions close to a real incident, the organization does not know how long recovery will take, which services may remain blocked, or what additional risks may appear during the crisis. In the DIAMATIX Operational Resilience series, we explore why recovery must be proven, not only planned. Read more here.

How This Type of Incident Can Develop

Attacks against public registers usually have several possible scenarios. Not all are confirmed in the ANCPI case, but they are important for risk assessment.

The first scenario is credential compromise. If an attacker obtains valid user credentials, they may appear as a legitimate user while moving through systems.

The second scenario is exploitation of known vulnerabilities. Unpatched systems, legacy applications, misconfigured servers or publicly exposed administrative interfaces can provide initial access.

The third scenario is ransomware or destructive activity. In this case, the goal is not only data theft, but service disruption, system destruction or pressure through extortion.

The fourth scenario is compromise of source code or internal documentation. This may help the attacker understand architecture and plan future activity.

This is why recovery should not simply mean “bringing systems back online.” It should include access review, application integrity checks, backup security, credential review and forensic analysis.

Recommended Actions

Organizations that manage public registers, critical databases or high-impact services should use this case as a control point.

Priority actions include:

  • identify all critical registers and dependencies;
  • check which services stop if the core system becomes unavailable;
  • test backup and restore processes, not only backup existence;
  • isolate backup infrastructure from production;
  • enforce MFA (Multi-Factor Authentication) for administrative access;
  • review all privileged accounts;
  • check for weak, reused or compromised credentials;
  • maintain an active vulnerability management process;
  • prioritize patching for systems and internet-facing applications;
  • centralize logs in a SIEM (Security Information and Event Management);
  • prepare an incident response playbook for destructive attacks;
  • create a clear incident communication model;
  • separate officially confirmed facts from unconfirmed claims in public updates.

For institutions and businesses dependent on external public registers, fallback procedures matter: what happens if a register is unavailable for 24, 48 or 72 hours?

DIAMATIX Perspective

The ANCPI incident shows why public registers should be protected as critical digital infrastructure.

The risk is not only potential data loss. The risk is service interruption, lack of access, loss of trust and delayed processes that depend on the register.

DIAMATIX treats cases like this as a resilience issue: backup, restore, visibility, access control, vulnerability management and response readiness need to work together.

CISO Analysis

For CISOs, the key question is whether critical registers and internal systems can be recovered in a verifiable and timely way.

Key questions to review:

  • Which systems are critical for service continuity?
  • Do we have a tested backup and restore process?
  • Are backups isolated from production?
  • Do we know which credentials can access critical registers?
  • Do we monitor compromised credentials and weak passwords?
  • Do we have centralized logs if local systems are deleted?
  • How do we respond to destructive attacks or ransomware?
  • Do we have a communication plan for unconfirmed claims?

The practical takeaway: for critical public services, cybersecurity should be measured not only by prevention, but also by recovery, evidence and continuity.

What This Means for Your Environment

  • This type of risk relies on dependency on critical registers, credentials, legacy systems, backup processes and public-facing services.
  • Detection depends on visibility into access, vulnerabilities, system logs, suspicious activity and changes in critical applications.
  • Response requires isolated backups, centralized logs, forensic analysis, recovery from a clean environment and clear communication.

Key questions to review:

  • Do you know which services cannot operate without a specific public or internal register?
  • Have you tested recovery from backup in a realistic scenario?
  • Can your SOC see lateral movement toward critical systems?
  • Do you have a plan if a core database or application becomes unavailable for several days?
  • Can you separate confirmed facts from claims during crisis communication?

 

Review the resilience of critical systems before an incident tests it for you

DIAMATIX can help review:

  • backup and disaster recovery readiness;
  • critical systems and dependencies;
  • privileged access and credentials;
  • vulnerability management processes;
  • SOC/MDR visibility over critical assets;
  • incident response playbooks for ransomware and destructive attacks;
  • communication readiness during incidents.

Request a resilience readiness review with DIAMATIX.
Trusted · Innovative · Vigilant


Sources

  • ANCPI. Official communications on the cyber incident.
  • AGERPRES. ANCPI cyberattack and e-Terra outage coverage.
  • Radio România Actualități. DNSC comments on the ANCPI incident.
  • TVR Info. ANCPI services unavailable; databases reported as not affected.
  • Risky Business. Reporting on unconfirmed claims regarding wiped systems and ByteToBreach.

This article is based on publicly available information as of July 2026. Unconfirmed claims are presented separately from officially confirmed facts.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.