Cyberattack cripples Romania's land registry, freezing property market before VAT deadline

A cyberattack that has taken Romania's National Agency for Cadastre and Land Registration (ANCPI) offline since July 14 has disrupted property transactions nationwide, as buyers rush to complete purchases before a temporary reduced VAT rate expires at the end of the month.
All IT systems managed by ANCPI, including the e-Terra cadastre and land registry platform and the agency's email services, remain unavailable. In an update on July 20, ANCPI said it could not yet estimate when normal operations would resume.
The outage comes as many buyers seek to finalise transactions before pre-sale agreements signed under the reduced 9% VAT regime expire at the end of July, after which the standard 21% rate will apply to eligible transactions.
Because Romania's cadastral and land registry system is fully digital, authorities cannot register new property transactions, process existing applications, or issue the land registry extracts required for home sales and mortgage registrations.
ANCPI said its systems were being migrated to the Government Cloud, a process expected to be completed on July 22, according to Profit.ro. Once migration is finished, the agency said, authorised institutions would verify the applications and data and draw up a report on the systems' status and any further measures needed, after which ANCPI would be able to give an estimated timeline for restoring services.
The agency added that it was prioritising the isolation of affected systems and the remediation of security vulnerabilities before gradually restoring operations.
A hacker using the alias ByteToBreach has claimed responsibility, posting screenshots on a cybercrime forum that allegedly show unauthorised access to ANCPI's infrastructure, according to ProTV.
Cybersecurity specialists cited by the broadcaster suggested the attack was financially motivated. Israeli cybersecurity firm KELA, cited by Profit.ro, described the individual as a technically sophisticated cybercriminal involved in trading sensitive data taken from airlines, banks and government institutions.
ANCPI has maintained that no confidential information was compromised, describing the attack in a July 15 statement as the largest technical disruption in its history and insisting that the data it administers was safe and had not been compromised.
That account has been challenged, however. KELA and other researchers have reported that the attacker deleted the land registry database after a failed extortion attempt, with recovery aided by offline backups the agency said it held at several locations.
Dan Cîmpean, head of Romania's National Cyber Security Directorate (DNSC), told Romanian outlet G4Media that the attack was not complex and could have been prevented, exploiting known vulnerabilities that authorities had recently warned organisations to patch, together with previously leaked credentials. He said investigators had so far found no evidence that personal data or land registry certificates had been stolen, though the attackers had allegedly exfiltrated a limited amount of information, including user credentials and application source code.
Unlock premium news, Start your free trial today.



