After a failed extortion attempt, a cybercriminal deleted Romania's entire land registry database. This was reported on Monday by the online portal Risky Business. According to the report, the attacker first gained access to the National Agency for Cadastre and Real Estate Advertising ANCPI (Agenția Națională de Cadastru și Publicitate Imobiliară), the country's land registry authority, and later attempted to sell the stolen data in specialized internet forums.
As Risky Business reported, citing unnamed sources, the cybercriminal gained access to the ANCPI database with valid credentials and explored the internal systems. After the extortion of the authority failed, he finally deleted all systems and backups, according to his statements. According to the online portal Cybernews, the attacker boasted in the Dark Web that he had manipulated backup copies of the stolen data to prevent their recovery.
The Romanian Land Registry initially spoke of technical problems but then had to admit to being the victim of a cyberattack. The incident became public on July 14. One day later, some stolen ANCPI data were offered for sale in a relevant internet forum, including access data of employees, internal documents, and details about the authority's IT network.











