Lithuanian prosecutors are investigating a major breach of the state registry systems after attackers used login credentials assigned to authorized institutions to access more than 600,000 records held by the Centre of Registers. The intrusion affected the Real Estate and Legal Entities Registers and exposed sensitive personal and property data, including names, dates of birth, national identification numbers, addresses, cadastral information, and registry numbers. Authorities said the breach was detected in early April, but disclosure was delayed while the criminal investigation proceeded, and the estimated financial damage exceeds €111,000.
Lithuania has blocked suspected accounts and ordered credential changes as it works to contain the incident, while questions over the security of state IT systems intensified. Centre of Registers chief Adrijus Jusas resigned following the leak and said years of underinvestment had left government platforms in need of as much as €60 million in cybersecurity upgrades. Officials have not publicly attributed the attack or identified a responsible threat actor, despite political claims that the operation may show signs of foreign, possibly Russian, involvement.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Centre of Registers chief Adrijus Jusas resigned amid scrutiny over the major data leak. He said years of underinvestment had left state IT systems needing up to €60 million in cybersecurity upgrades.
Prosecutors began investigating the major breach of the country's state registry systems involving the theft of more than 600,000 records from the Centre of Registers. Officials said the attackers had exploited credentials belonging to authorized institutions.
In response to the breach, Lithuania blocked suspected accounts and required credential changes for affected access holders. Authorities also estimated the financial damage from the incident at more than €111,000.
Officials detected the breach in early April after unauthorized access to state registry systems was identified. Public disclosure was delayed while a criminal investigation proceeded.
A foreign actor abused login credentials assigned to authorized institutions to access the Centre of Registers' Real Estate and Legal Entities Registers. The theft exposed more than 600,000 records containing personal and property information, including names, dates of birth, national ID numbers, addresses, cadastral data, and registry numbers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.