Hacker Wipes Romania's Entire Land Registry Database After Failed Extortion

Hacker wipes Romania's land registry database

Hacker Wipes Romania's Entire Land Registry Database After Failed Extortion

A hacker known as ByteToBreach breached Romania's National Agency for Cadastre and Real Estate Advertising, wiping the entire land registry database after an extortion attempt failed. The attack has paralyzed the real estate market, halting transactions and blocking access to ownership records. While the agency is rebuilding its network from scratch, the hacker, identified as Zakaria Mahdjoub from Algeria, leaked sensitive internal data on a forum.

Well, that will make the job of Romanian law enforcement a hell lot easier!
  1. skinfaxi

    > Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.

    So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.

  2. cbg0

    An update from the land registry (the truthfulness of this remains to be seen depending on how fast this comes back online):

    ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.

    After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.

    ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.

    According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.

    The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal inves […]

  3. alexpotato

    Romanian friends have told me that this is really due to corruption.

    Specifically:

    - government gives IT/data contracts to cronies

    - cronies don't actually do any real security work to protect the data

    - things like this happen

  4. khurs

    Security firm KELA... has doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria.

    If I was an evil hacker, I would only hack countries my country hated or did not have extradition agreements with. Like the Russian hackers do.

    Algeria has a extradition treaty with Romania:

    https://periodicos.processus.com.br/index.php/egjf/article/v...

  5. rzerowan

    Tangentially reminds me of what happened to the South Korean gov data center [1] where a no-backup ~900TB data center got erased due to a battery fire.

    Withno external backups piecing together all the lost functions must havebeen hair raising, and more forensic archeolgy than data recovery.

    Last i heard i think they had restored a quarter of the lost services/data.

    [1] https://www.intermediagroup.org/south-korea-data-loss/

  6. puritanicdev

    Well, the land registry database in Serbia hasn't been working for two months now; the government hasn't issued any announcement so far, except for generic system-issue information we get from LRD support. Weird, hopefully we weren't hit too

  7. osinix

    The backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.

  8. dredmorbius

    Poor password practice and policy, and likely a lack of 2FA / physical token security, seem to have contributed to this breach.

    Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:

    <https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...>

    <https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...>

    Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>.

    NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.

  9. Squarex

    The same thing happened to Slovakia not that long ago.

  10. henrycoler

    He is no scam,I tested him and he delivered a good job,he helped me settle bank loans,he also helped my son upgrade his scores at high school final year which made him graduate successfully and he gave my son free scholarship into the college,all I had to do was to settle the bills for the tools on the job,I used $500 to get a job of $50000 done all thanks to [email protected],he saved me from all my troubles,sharing this is how I can show gratitude in return for all he has done for me and my family

More from this day

2026-07-20