A 45-year-old Romanian national, Catalin Dragomir, pleaded guilty in U.S. court to hacking computers at Oregon’s Department/Office of Emergency Management in June 2021 and then selling the access for about $3,000 in Bitcoin. Prosecutors said Dragomir operated as an initial access broker, using online monikers including “inthematrixl” to advertise and negotiate sales of administrative credentials on cybercriminal platforms; he repeatedly accessed the victim network to prove the access was valid and provided screenshots and login details.
Dragomir also admitted to hacking 10 other U.S. companies, with total losses cited at at least $250,000. He was arrested in Romania in November 2024, extradited to the U.S. in 2025, and pleaded guilty to obtaining information from a protected computer and aggravated identity theft; sentencing is expected in May, and he faces up to seven years in prison. The case highlights a relatively uncommon prosecution outcome for a municipal/government network intrusion tied to the sale of stolen credentials and access.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
U.S. authorities scheduled Dragomir's sentencing for May 26, 2026. He faces up to seven years in prison.
Dragomir pleaded guilty to obtaining information from a protected computer and aggravated identity theft for the 2021 Oregon intrusion and sale of access. The plea also acknowledged his role in compromising other U.S. victim networks.
After his arrest in Romania, Dragomir was extradited to the U.S. to face charges related to hacking Oregon's emergency management department and selling the stolen access. Multiple reports place the extradition in January 2025.
Dragomir was arrested in Romania in connection with the Oregon breach and other intrusions into U.S. victims' networks. Prosecutors alleged his activity affected 10 other U.S. companies and caused at least $250,000 in losses.
After obtaining access, Dragomir advertised the Oregon state network access on cybercriminal platforms under the moniker "inthematrixl" and negotiated its sale for $3,000 in Bitcoin. During the sale, he shared samples of personally identifying information from the compromised system with a prospective buyer.
Catalin Dragomir gained unauthorized administrative access to Oregon's emergency management network in June 2021. Prosecutors said he repeatedly re-entered the system to prove the access remained valid and extracted personal information from it.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.