Cyberattack Paralyzes Real Estate Transactions in Romania
A cyberattack on Romania’s National Agency for Cadastre and Real Estate Advertising (ANCPI) knocked out the agency’s key information systems and effectively halted real estate transactions across the country. A hacker using the alias ByteToBreach claimed to have stolen internal data and source code, Cybernews reports.
Hacker Demanded Payment and Began Deleting Data
ANCPI officials initially attributed the shutdown of its information systems to technical problems. The agency later acknowledged that it had been hit by a cyberattack. ByteToBreach wrote on a hacking forum that he had gained access to databases containing information on Romanian citizens and copied GitLab servers storing the source code of ANCPI systems, including e-Terra and RENNS.
The attacker is believed to have gained access to the infrastructure using valid credentials. He attempted to extort money from ANCPI, but the effort failed. The hacker then began deleting information available to him, including internal documents and employee credentials. He also claimed to be destroying backup copies to make system recovery more difficult.
An official investigation later clarified the scale of the attack. Romanian authorities confirmed the use of ransomware: parts of the virtualization infrastructure hosting ANCPI applications were encrypted and deleted. However, the central cadastral database containing information on real estate in Romania and registered property rights was not affected. The agency said backup copies had been stored at several separate locations, allowing the information to be restored after the cyber incident.
Cyber intelligence company KELA believes the ByteToBreach account is likely operated by Zakaria Mahdjoub from Oran, Algeria. Researchers describe him as a technically skilled cybercriminal who sells confidential data belonging to banks, airlines and government organizations. ByteToBreach has also been linked to the hacking of Sweden’s e-government portal earlier in 2026. Researchers suspect that he may have been involved in attacks on government registries in Slovakia, Ukraine, Poland and Lithuania. These findings are based on cybersecurity experts’ analysis and have not yet been officially confirmed by law enforcement agencies.
Impact of the Attack on Romania’s Real Estate Market
The consequences of the attack quickly extended beyond ANCPI itself. Notaries were unable to obtain land registry extracts, authenticate sale and purchase agreements or register mortgages. The scale of the disruption was significant: between 150,000 and 170,000 properties are sold in Romania each year on average. In addition, e-Terra is used for more than changes of ownership. The disruption also affected banks, developers, cadastral specialists and other procedures requiring official registration.
The outage also came at a sensitive time for the market. From August 1, VAT on new housing in Romania increased from 9% to 21%. A transition period allowing some homebuyers to complete previously agreed transactions at the 9% rate was about to expire. Because the cadastral system was unavailable, some buyers were physically unable to complete the necessary paperwork before the deadline.
The authorities consequently extended the deadline for eligible transactions to be completed at the 9% VAT rate until September 30, 2026. The measure applies to buyers who meet the transition requirements, including those who signed a preliminary agreement before August 1, 2025.
Marc Bălășescu, co-founder and CEO of Intrudify, described e-Terra as a critical point in the entire system, noting that the shutdown of a single government service simultaneously disrupted the work of numerous market participants.
Around 0.2% of the IT Budget Was Spent on Cybersecurity
Following the attack, attention turned to the level of protection surrounding ANCPI’s information systems. An analysis by Ziarul Financiar shows that since the electronic cadastral system was launched in 2007, the agency has signed contracts worth around 710 million lei, or €163 million, for IT and archive digitization. About 516 million lei was spent on software and hardware, services and maintenance, while almost 200 million lei went toward scanning and indexing paper land registry records. Projects directly related to cybersecurity accounted for less than 1.6 million lei over seven years — around 0.2% of total spending.
Dan Cîmpean, director of Romania’s National Cyber Security Directorate (DNSC), said the attack was not technically sophisticated and could have been prevented. The hacker exploited vulnerabilities that DNSC specialists had warned the cadastral agency about shortly before the incident. Andrei Avădănei, founder and CEO of Bit Sentinel, attributed the breach to insufficient segmentation of the internal network and the accessibility of critical resources.
Romania’s acting economy minister, Irineu Darău, also called for stronger cyberattack prevention measures. While such risks cannot be eliminated entirely, government institutions should treat information security as one of their highest priorities, he said.
System Restored After Four Weeks
Recovery of e-Terra began on August 11, nearly a month after the attack. On the first day after the restart, 24,695 applications were registered in the system. Cadastral office staff and notaries regained access, and once land registry extracts became available again, real estate transactions could resume. The authorities decided to reconnect ANCPI’s other online platforms gradually after additional security checks. During the first week after its relaunch, e-Terra received 205,995 applications. ANCPI attributed the heavy workload to requests that had accumulated during the outage.
International Investment analysts note that the cyberattack did not destroy Romania’s official property rights register, but it disrupted the real estate market nationwide. The failure of one key government system was enough to halt the registration of transactions and mortgages and create difficulties for notaries, banks, developers and buyers.
The attack also prompted additional scrutiny of government institutions and the protection of critical infrastructure. Romania’s experience may serve as a warning to other countries: as electronic registries expand, the consequences of cyberattacks are increasingly extending beyond the IT sector and affecting entire industries.
