preloader

· digital-security backup-and-recovery incident-response europe cloud devops

A Failed Extortion Attempt Wiped Romania’s Entire Land Registry, and Only an Offline Backup Saved It

Source: Cybernews / The Record / Help Net Security

A threat actor operating under the alias ByteToBreach, since identified by researchers at KELA as Zakaria Mahdjoub, gained access to Romania’s National Agency for Cadastre and Real Estate Advertising, known as ANCPI, using valid login credentials rather than a software exploit. Once inside, the attacker exfiltrated citizen data, internal documents, employee credentials and the source code for ANCPI’s Eterra and RENNS systems, then attempted to extort the agency. When the extortion attempt failed, the attacker wiped the agency’s production land registry database on 14 July.

An entire EU country’s property market stalled overnight

ANCPI’s systems underpin every property transaction in Romania. With the registry down, notaries could not authenticate document signatures, register new property sales or record new mortgages, effectively freezing a large part of the country’s real estate market at short notice, and during a period when the market was already under pressure ahead of a VAT deadline. This is not a niche internal IT outage; it is critical national infrastructure for an EU member state, taken offline by a single set of stolen or misused credentials.

The only thing that stopped this becoming permanent

ANCPI has confirmed the attacker did not manage to destroy all of its data, because the agency stores backups in multiple separate locations. That is the detail worth sitting with: the difference between a bad week and a genuinely unrecoverable national incident came down to backup architecture that had already been decided, tested and paid for long before the attack happened. Plenty of organisations, public and private, cannot say the same. If a single compromised credential gave an attacker write access to your production database and your backup targets at the same time, would you still have something to restore from?

The lesson for every organisation running production data

Valid-credential intrusions are increasingly common precisely because they bypass most perimeter defences entirely; the attacker does not need a zero-day if they can simply log in. The controls that actually limit the damage are the boring ones: least-privilege access so one compromised account cannot reach production and backups alike, offline or immutable backup copies that a logged-in attacker cannot delete, and a tested restore process so recovery time is measured in hours rather than weeks.

If you want an honest assessment of whether your organisation’s backup and access architecture would survive a scenario like this, contact Excello Digital. We help European businesses design credential and backup strategies that assume an attacker will eventually get valid access, and make sure that access alone is not enough to cause irreversible damage.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!