Ransomware attack on Romania's cadastre agency ANCPI shuts down the national land registry
What happened
On 14 July 2026 Romania's National Agency for Cadastre and Land Registration, ANCPI, detected unauthorised access to its IT infrastructure. In a communique of 27 July the Romanian government stated that the technical investigation had confirmed a ransomware attack in which the attackers encrypted and deleted part of the virtualisation infrastructure hosting the agency's applications, and that the affected systems were isolated after the National Cyber Security Directorate, DNSC, intervened to stop the attack spreading.
The outage took down the e-Terra cadastre and land register application, agency e-mail and the ePay payment platform. Notaries could not authenticate property sales or register mortgages and citizens could not obtain proof of ownership, which brought much of the Romanian property market to a standstill for weeks. The government said the central cadastral database was not affected, that there was no evidence the attackers had reached that data and that the integrity of the records was confirmed. It gave no date for the restoration of service and said the systems would be rebuilt in the government cloud.
In a statement of 30 July ANCPI confirmed the same account and listed additional measures including network segmentation, multi-factor authentication and continuous monitoring. Users of the ePay portal were advised to change their passwords.
Assessment
No group has been named, no ransom demand has been made public and no state attribution has been made. The Romanian authorities treat this as criminal ransomware, and identifying the attackers is the subject of an ongoing criminal investigation. DNSC director Dan Cîmpean said publicly that the attack was not complex and could have been prevented, pointing to known unpatched vulnerabilities previously flagged to the agency and to credentials that had leaked online. The case shows how one unpatched public registry can halt a national property market. Sixteen days later ransomware also hit the National Prison Administration, an attack DNSC says is technically unrelated.
This dossier summarises open-source reporting and is updated as the investigation develops. Read the original report via the source link.