Romania’s National Agency for Cadastre and Land Registration (ANCPI) confirmed that the outage affecting its e-Terra cadastre and land registry platform was caused by a cyberattack, disrupting property and real-estate transactions while the agency worked to restore services. ANCPI said the application would likely remain unavailable until the end of the week and stated that, based on its ongoing investigation, data managed through its IT systems had not been compromised.
At the same time, a threat actor using the alias ByteToBreach advertised alleged ANCPI data for sale on a dark web forum, claiming to have breached the agency’s internal network, stolen Romanian citizens’ cadastre and property records, copied GitLab servers and source code for core systems, and deployed ransomware. Those claims were not independently verified, but the actor has previously been profiled as a credible, opportunistic data-leak operator that targets high-impact organizations and monetizes stolen information through underground forums and public-facing channels.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
ANCPI began migrating affected applications to the Romanian government cloud and said it would verify system integrity before gradually restoring services after the cyberattack. Romanian officials also said the intrusion appeared financially motivated and involved exploitation of known vulnerabilities and leaked credentials.
ANCPI confirmed that the outage affecting its e-Terra cadastre and land registry application was the result of a cyberattack, after initially describing the disruption as a major technical incident. The agency said its investigation was ongoing, stated that data under its administration had not been compromised, and warned the platform would likely remain unavailable until the end of the week.
A threat actor using the alias ByteToBreach posted a listing advertising data allegedly stolen from Romania’s National Agency for Cadastre and Land Registration (ANCPI), claiming compromise of the internal network, theft of citizen cadastre and property records, source code access, and ransomware deployment. The claims were reported as unverified.
According to the new report, ANCPI's breach became public on July 14 as an attacker allegedly began wiping the country's land registry database and backups after a failed extortion attempt. The incident reportedly disrupted ANCPI apps, websites, and email systems and halted parts of Romania's real-estate transaction process.
KELA assessed that the actor using the handle “ByteToBreach” had been active since at least June 2025, using multiple underground and public platforms to sell and leak stolen data from organizations in several sectors worldwide.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
news.risky.biz
Open sourcetherecord.media
Open sourcehelpnetsecurity.com
Open sourcedarkwebinformer.com
Open sourcekelacyber.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.