Romania's national water management agency, Administrația Națională Apele Române (Romanian Waters), suffered a significant ransomware attack that compromised around 1,000 systems, including servers, workstations, and critical IT infrastructure. The attackers used Microsoft's BitLocker, a legitimate Windows encryption tool, to lock files and left ransom notes demanding negotiations within seven days. Despite the widespread IT disruption, operational technologies such as dams and flood defenses remained unaffected, and hydrotechnical operations continued with staff relying on alternative communication methods like telephone and radio due to email outages. Authorities have not attributed the attack to a known ransomware group and have advised against negotiating with the attackers.
The Romanian National Cyber Security Directorate (DNSC) confirmed that the attack impacted ten of the country's eleven river basin management organizations, but emphasized that water infrastructure operations were not disrupted. The use of BitLocker as a "living off the land" technique highlights a trend where attackers leverage built-in system tools to evade detection and complicate incident response. The DNSC reiterated its policy of not engaging with cyber extortionists and urged IT teams to focus on system restoration rather than external communications. The agency continues to investigate the incident and work towards full remediation of affected systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Following the attack, authorities began efforts to connect Romanian Waters to Romania’s national critical infrastructure cyber protection and monitoring systems. Reporting said the agency had not been covered by that protection framework at the time of the incident.
By 2025-12-22, Romanian Waters publicly confirmed the cyberattack and stated that critical water operations continued without interruption despite widespread IT outages. Public reporting also noted that the initial intrusion vector and responsible actor were still unknown.
During the incident response, DNSC publicly advised Romanian Waters not to negotiate with the attackers. Officials focused on restoration and containment instead of engaging with the ransom demand.
Because email and other IT services were disrupted, staff switched to telephone and radio communications while hydrotechnical operations continued locally. Operational technology controlling dams, flood defenses, and water services was not affected.
Investigators determined the attackers used Microsoft BitLocker to encrypt files rather than custom ransomware tooling. A ransom note was left instructing the victim to make contact within seven days, though no group publicly claimed responsibility.
Romania’s National Cyber Security Directorate (DNSC) was notified of the incident on 2025-12-20 and began coordinating response and remediation efforts. Other national authorities, including intelligence and cyber response bodies, also joined the investigation.
On 2025-12-20, Romania’s National Water Administration (Romanian Waters) was hit by a ransomware attack affecting its central organization and 10 of 11 regional water basin administrations. About 1,000 IT systems were impacted, including servers, workstations, GIS, database, email, web, and DNS systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehackread.com
Open sourcedatabreaches.net
Open sourcetomshardware.com
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.