A hacker deleted Romania’s entire national land registry database after the agency refused to pay an extortion demand, bringing the country’s real-estate market to a standstill. The attacker — operating under the alias ByteToBreach — logged into the systems of ANCPI, Romania’s National Agency for Cadastre and Real Estate Advertising, using valid credentials, mapped the internal network, and then wiped the database along with the agency’s email servers. More than a week later, Romanians still could not obtain proof of property ownership.

What happened

The destruction began around July 14, 2026. Rather than deploying a novel exploit, the attacker simply authenticated with legitimate credentials — the same pattern behind a growing share of the most damaging intrusions, where the “vulnerability” is an identity, not a software bug. Once inside, ByteToBreach reconnoitered ANCPI’s systems and then destroyed the core land registry database. Stolen records began surfacing on hacking forums by July 15.

The trigger was a failed extortion attempt. When the agency declined to pay, the attacker moved from theft to sabotage — a destructive escalation increasingly common when ransomware and extortion crews don’t get their payout. The attacker claims to have wiped backups as well as production systems; Romanian officials indicate an offline copy of the data existed, which is likely the only thing standing between a week-long outage and permanent loss.

The real-world fallout

ANCPI is not a peripheral system — it is the legal source of truth for who owns what in Romania. With it offline:

  • Notaries could not authenticate property sales, issue land extracts, or register mortgages.
  • Property purchases stalled nationwide; buyers and sellers were left unable to close.
  • Citizens could not obtain proof of ownership — the document required for everything from selling a home to settling an inheritance.

Official apps and websites were down for over a week. This is the defining feature of attacks on land registries: the damage is not measured in leaked records but in a frozen economy. A country cannot transact real estate without a functioning cadastre.

Who is behind it

Threat-intelligence firm KELA identified ByteToBreach as Zakaria Mahdjoub, a cybercriminal based in Oran, Algeria. The actor has a track record of breaching government and corporate targets and leaking or selling the data, and the ANCPI incident fits the extort-then-destroy playbook.

Part of a European pattern

Romania is not an outlier. National land and property registries have become a recurring target across Europe and beyond over the past three years:

  • Slovakia’s national land registry was knocked offline by a major ransomware event in 2025.
  • Lithuania’s State Register Center was infiltrated in May 2026, with over 600,000 real-estate records downloaded.
  • Poland, Greece, Morocco, Russia, and Ukraine have all seen registry-agency breaches in the same window.

The logic is grimly straightforward: land registries are high-impact, often under-funded, and legally irreplaceable. Encrypting or deleting one paralyzes a national market instantly, giving an extortionist maximum leverage — and when the leverage fails, maximum destructive spite.

The takeaways

  • Identity is the perimeter. Valid credentials, not a zero-day, opened the door. Phishing-resistant MFA on every administrative account and aggressive monitoring for anomalous logins are the controls that would have mattered most.
  • Offline, immutable backups are survival infrastructure. The difference between Romania’s week-long outage and a permanent catastrophe appears to be a single offline copy. Attackers now specifically hunt and delete backups; if yours are reachable from a compromised admin session, they are not backups.
  • Critical civic databases need destruction-grade resilience. Registries, cadastres, and vital-records systems should be treated as critical national infrastructure, with tested restoration playbooks measured in hours, not weeks.

Romania says it is rebuilding the agency’s entire network from scratch. For a country’s property market, that is the most expensive possible way to learn that a backup you can’t restore from — and a credential you didn’t protect — will eventually cost you everything.

Sources