Romania's Property Market Froze Because Nobody Tested the Backup
ANCPI had valid-credential access wiped clean and an offline copy it had never proven could restore. Everyone will call this a security incident. The recovery failure is the part that will happen again.

Every notary in Romania woke up on July 15 unable to close a sale, authenticate a mortgage, or prove who owns what. Not because of a nation-state. Not because of a zero-day. Because one person with valid credentials deleted everything after a ransom demand went unanswered.
This is the incident everyone in government IT will cite in budget meetings for the next two years. Most will cite it wrong.
What Actually Happened
On July 14, 2026, Romania's National Agency for Cadastre and Real Estate Advertising (ANCPI) suffered a critical cyberattack that resulted in the complete wiping of the country's land registry database. The hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency. A day later, stolen data—employee credentials, internal documents, IT network details—appeared on a hacking forum.
The hack brought Romania's entire real-estate market to a standstill for a week. Notaries could not record transactions while citizens could not obtain proof of ownership. The agency disclosed what it called "the most serious technical incident in the institution's history."
The attacker found no novel vulnerability. There is no evidence that specific software versions were exploited; the breach was facilitated by valid credentials. This was a deletion operation. The sophistication required was logging in and pressing delete.

The Part Everyone Will Miss
ANCPI had backups. Read that again.
ANCPI's press release states: "Contrary to some information appearing in the public space, at the time of the incident, the ANCPI had several locations designated for storing backup copies, a measure that ensures redundancy and the possibility of data restoration in the event of cybersecurity incidents."
Translation: we had the backups. We just could not use them fast enough to prevent a week-long national property market freeze.
A backup you have never restored under load is not a backup. It is a hypothesis.
The agency began migrating its applications to the Romanian government cloud, a process expected to finish days after the incident, after which authorities would verify system integrity before gradually restoring services. Adrian Vascu, Senior Partner at Romanian business advisory firm Veridio, argued that the disruption exposes a deeper problem: digitalized systems built without backup provisions for when they fail. "A failure can happen at any time, but it is mandatory to ensure continuity or an alternative," he wrote.
He is right. He will be ignored by most of the people who need to hear it.
ANCPI had the hypothesis. Romania's property market discovered the gap between hypothesis and reality in real time, with real money and real legal consequences for people trying to close transactions.
What You Should Actually Do With This
If you run infrastructure a country, city, or company cannot function without, three questions matter now. First: can an authenticated user with valid credentials delete everything you own? If access control does not distinguish between read, write, and destroy at a granular level, the answer is yes. Second: when did you last actually restore from your backup, not just verify its existence? Third: how long does your recovery take under real conditions, with real data volumes, at 2am, with your best engineer asleep?
Romania is going to buy more monitoring. It is migrating to the government cloud. Neither addresses what actually broke: the gap between "backup exists" and "we can recover in hours" turned out to be measured in days of national economic paralysis.
Every backup and disaster-recovery vendor will use this story in a sales deck before the month is out. Most will sell storage, not discipline.
Storage is easy. The hard part is the drill.
Schedule it. Make someone responsible for the result. Accept that it will be ugly the first time. Run it anyway.
What to watch: Whether ANCPI's remediation includes a documented, timed, witnessed recovery test before declaring services fully restored. Whether other EU member states now audit their land and civil registry recovery procedures under something harder than a checklist. And whether the ByteToBreach actor, doxxed as Zakaria Mahdjoub from Oran, Algeria, results in an extradition that actually lands—because the enforcement signal matters as much as the technical one.
- Hacker wipes Romania's entire land registry database — Risky Business
- Hacker deletes country's entire land registry database after failed extortion attempt — Cybernews
- Romania races to restore land registry after cyberattack disrupts property market — The Record
- Romania ANCPI Land Registry Wiped in Credential-Based Cyberattack — Rescana
- Romania's land registry hit by cyber attack, data allegedly for sale — Help Net Security
- Hacker Wipes Romania's Entire Land Registry Database - Slashdot
- Slashdot: News for nerds, stuff that matters
- Hacker wipes Romania's land registry database | Hacker News
- Risky Bulletin: Hacker wipes Romania's entire land registry database - Risky Business Media
- Romania Land Registry Cyberattack Spurs ByteToBreach Data-Theft Claims | Mallory
- Two Confirmed Attacks in Three Days