On 14 July 2026, Romania's National Agency for Cadastre and Real Estate Advertising (ANCPI), the government body that maintains the country's land registry and property records, watched its own database disappear in real time. The agency had told the public its systems were down for "technical problems." They were not. A hacker operating under the alias ByteToBreach had been inside ANCPI's network for some time, and when an extortion demand went unpaid, the attacker began wiping the registry live, posting a message to a hacking forum announcing the deletion as it happened.
The attacker reportedly entered ANCPI's systems using valid credentials, then mapped the agency's internal network before exfiltrating a wide set of data: citizen records held across ANCPI's databases, the source code behind the agency's core Eterra and RENNS platforms taken from its GitLab servers, and internal employee credentials. A day after the deletion began, some of the stolen material was already listed for sale on a hacking forum. Cybersecurity firm KELA has since identified the person behind the ByteToBreach alias as Zakaria Mahdjoub, based in Oran, Algeria, the same individual linked to an earlier breach of Sweden's e-government portal this year.
The damage to Romania's property market was immediate and total. Notaries could no longer authenticate a sale, register a mortgage, or issue a land registry extract. One notary put it plainly days into the outage: since the attack began, she could do none of those things. Romania's real estate market processes between 150,000 and 170,000 residential transactions a year, and for the length of the outage, none of them could proceed through the normal channel. ANCPI's email systems and public-facing services went dark alongside the registry itself, and the agency has spent the period since rebuilding its network from scratch.
The incident sits inside a wider pattern. The operator behind ByteToBreach has separately been linked to breaches of government registries in Slovakia, Ukraine, Poland and Lithuania, and land registry agencies specifically have now been hit in Romania, Poland, Slovakia, Greece, Morocco, Russia and Ukraine over the past three years. National property registries have become a recurring target precisely because the record they hold, who owns what, is both sensitive and functionally irreplaceable once lost.
ANCPI was not defenceless. The agency has confirmed it held offline backup copies of its data across multiple locations, a measure that limited what could have been a total and permanent loss of the country's land records. That backup discipline is the reason Romania is rebuilding its network rather than reconstructing property ownership from scratch. But nothing in that defence sat at the point that mattered most: the moment a valid login was used to begin deleting a national database. Access controls, once satisfied at the point of entry, did not ask again before the destructive action executed.
A bulk deletion of a government's live land registry is an execution event. Under GoFirm, before a command capable of wiping or materially altering production data at that scale can run, a confirmation request goes to the named authority responsible for that system, on their registered device, requiring a real-time biometric response. No confirmation, no execution. It makes no difference whether the login carrying out the command holds a valid password, a valid session token, or a valid set of credentials obtained by any means. The control sits after authentication and before the action, at the point where the consequence becomes irreversible.
That is the distinction a stolen or misused credential cannot get around. ByteToBreach's access to ANCPI looked legitimate to every system it touched, right up until the moment the data was gone. A credential, however valid it appears, cannot produce a biometric confirmation on the named authority's registered device. The execution boundary holds regardless of how authentic the access looks.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Radauskas, G. 2026. Hacker wipes European country's entire land registry database, paralyzing real-estate market. Cybernews, 20 July 2026.
2. Cimpanu, C. 2026. Risky Bulletin: Hacker wipes Romania's entire land registry database. Risky Business News, 20 July 2026.
3. KELA. 2026. ByteToBreach: A Deep Dive into a Persistent Data Leak Operator. KELA Cyber Threat Intelligence, 2026.
