On 14 July 2026, an intruder with access to Romania's National Agency for Cadastre and Real Estate Advertising (ANCPI) did something most attackers don't bother with: having failed to extort the agency, they deleted what they'd stolen and, by most accounts, tried to take the backups with it. The result was the closest thing to a national real-estate shutdown the EU has seen in recent memory: notaries unable to authenticate a single sale, citizens unable to pull the paperwork proving they own their own homes, all because a government department's disaster recovery model assumed the wrong thing was hard to reach.
ANCPI will tell you the story ends well. It didn't, not quite, and the reason it didn't is more interesting than the breach itself.
ANCPI's press release, issued once the dust settled, said the agency had maintained several designated backup locations, providing redundancy and the ability to restore in the event of a cybersecurity incident. Read at face value, that's a Cyber Essentials-adjacent claim: multiple locations, redundancy, restoration capability. It's the sentence every compliance framework wants to see.
It also happens to be true; ANCPI does appear to have had an offline copy, and that copy is why Romania is looking at a week-long outage rather than a permanent loss of the national land registry. But "true" and "the whole story" aren't the same thing, and the gap between them is the point of this piece.
The reporting, primarily via Risky Business and a Rescana technical write-up, and corroborated by Romanian outlets including G4Media and Romania Insider, describes a straightforward chain:
The actor, using the handle ByteToBreach, posted the announcement on a hacking forum with the header "Thy arss shall be spanked, Romania! [ANCPI]", alongside claims of having taken a full copy of ANCPI's GitLab servers, covering the source code for the agency's core systems, e-Terra and RENNS.
KELA's threat intelligence team assesses, with medium confidence, that the campaign is likely operated by an individual named Zakaria Mahdjoub, based in Oran, Algeria; DNSC's own read is consistent, describing the attack as financially motivated with no indication of state involvement. It isn't ByteToBreach's first swing at a government target either; they previously breached Sweden's e-government portal. Nor is Romania alone in the target class: Risky Business's own reporting places Poland, Slovakia, Greece, Morocco, Russia, and Ukraine alongside Romania as countries whose land registry agencies have been hacked over the past three years, each by a different actor. Slovakia's cadastre office was taken down by a separate ransomware group in January 2025; Russia's Rosreestr was breached the same month by a group calling itself Silent Crow; Ukraine's own Ministry of Justice and land registry were hit by yet another actor around Christmas 2024. This is a sector under sustained pressure from multiple distinct actors, not one gang's rap sheet.
KELA's follow-up analysis is where this stops being "government agency gets hacked, film at eleven" and starts being genuinely useful for anyone running their own infrastructure.
The actor didn't just claim access; they published a dataset that maps ANCPI's internal Active Directory environment in enough detail for an outsider to plan a path to domain-level control without ever touching the live network. Sitting inside that dump: dependency on Windows XP, Windows 7, and Windows Server 2003 in a production government environment in 2026; at least 69 Group Policy Objects, including ones named, without apparent irony, "DISABLE WINDOWS FIREWALL" and "MIGRARE - ADD ADMINS"; dangerous AD permission relationships (GenericAll, WriteDacl, WriteOwner); and at least one encoded corporate password sitting in plaintext-adjacent form.
None of that is a sophisticated attack chain. It's a permissions model that gave up years before the breach happened. Whether the specific credentials used for initial access were the same ones harvested by infostealer malware that KELA separately identified against ANCPI accounts is, notably, something even KELA won't confirm; they flag it as plausible, not proven. That's worth sitting with: even the people who unmasked the actor won't overstate what they can and can't verify. More organisations doing incident write-ups could stand to borrow that discipline.
Here's the actual lesson, and it's not "Romania should have patched Windows Server 2003", although, yes, obviously.
The backups that got destroyed were destroyed using the same access that destroyed production. That's the tell. If your backup infrastructure trusts the same identity plane as your live systems (same domain, same credential set, same lateral-movement path once someone's inside), then "we have redundant backup locations" is a true statement that provides approximately none of the protection it implies. Redundant doesn't mean protected. It means there are more copies of the same trust boundary sitting around for an attacker to find during recon.
What saved ANCPI wasn't redundancy. It was the one copy that sat outside the credential's reach entirely: offline, not addressable by anything the attacker had. Isolation did the work that "multiple locations" gets credited for in the press release.
This is the distinction that gets flattened every time an organisation describes its DR posture in governance language rather than architecture language. "We have backups" and "we have backups an attacker with valid domain credentials cannot touch" are different claims, and only one of them survives contact with an actor who's done their reconnaissance.
For anyone running their own infrastructure rather than outsourcing the problem to a hyperscaler and hoping:
Romania got lucky that an offline copy existed. The press release reads as though it was the plan all along. Whether it actually was (whether ANCPI's backup architecture was deliberately isolated by design, or whether one copy simply wasn't reachable through the compromised account for reasons nobody had explicitly engineered) is not something the public reporting confirms either way. That's the gap this piece is really about.
The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy, with particular focus on Isle of Man jurisdiction and Crown Dependency issues.
Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.