Ransomware attack on Romania's National Prison Administration suspends inmate transfers
What happened
On 29 July 2026 Romania's National Prison Administration was hit by a ransomware attack that affected a number of workstations and servers. According to the agency's own communique its IT team immediately contacted the National Cyber Security Directorate, DNSC, which intervened to limit the impact, and all equipment was physically isolated.
As a precaution several services were taken offline, among them the IMS Web inmate management system, the Infokiosk terminals, the telephone service for detainees, the visit booking portal, the VPN connections between sites and the anp.gov.ro website. Transfers of detainees between penitentiaries were suspended and carried out only in urgent cases, and internal communication fell back on telephone and radio. Detainees were allowed calls of up to five minutes a day, and only to numbers they had used before the attack. Visit booking moved to the telephone and the counter, and court appearances shifted towards video link.
The agency said it would file a criminal complaint the same day with DIICOT, the Romanian organised crime and terrorism prosecution service, and that technical teams were continuing to work with the competent cyber security authorities.
Assessment
No group has been named officially and no ransom demand has been made public. DNSC director Dan Cîmpean said the Babuk group was the most probable perpetrator but that this could not be confirmed, described its members as Russian and English speaking, and stated explicitly that it cannot be tied to a state actor. He also said the attack was unconnected to the ransomware attack on the cadastre agency ANCPI two weeks earlier, because the tactics differed. Two state authorities compromised within sixteen days points at the patch and credential hygiene of Romanian public IT rather than at a single campaign.
This dossier summarises open-source reporting and is updated as the investigation develops. Read the original report via the source link.