
Romania’s Cadastre Attack Made Cyber Recovery a Property-Market Problem
A cyberattack against Romania’s land and cadastre agency disrupted national property services. The incident shows why recovery must restore legal confidence as well as technical availability.
Romania’s National Agency for Cadastre and Land Registration, ANCPI, suffered a major cyberattack on 14 July. The agency took systems including e-Terra and email offline, describing the event as the largest technical outage in its history.
Government updates confirmed unauthorised access and reported that parts of the environment were encrypted or deleted while recovery continued from protected data. Some reporting went further, describing a wholesale wipe after failed extortion. Because the agency disputed the most sweeping claims, they should not be presented as established fact.
The confirmed impact was already severe: land-registry and cadastre services became unavailable, affecting transactions and administrative work across the country.
Availability is not the only recovery target
A land registry is a system of public trust. It records rights and boundaries that support sales, mortgages, inheritance and public administration. Restoring a server is not sufficient if users cannot be confident that records are complete, current and legally reliable.
Recovery therefore needs three parallel proofs:
- technical integrity: systems and identities are clean;
- data integrity: restored records match trusted copies and subsequent changes are reconciled;
- legal continuity: registrars, notaries and courts know which records and timestamps are authoritative.
Publishing service status without explaining those proofs may bring systems online while leaving the market uncertain.
Backups need independence and meaning
ANCPI said its databases had backup protection and worked to restore services. Every public registry should test whether backup administrators, credentials and management planes are isolated from production.
The restore exercise must include application dependencies, document stores, indexes, signing keys, audit logs and interfaces used by local offices. A database that starts successfully may still be missing an attachment, transaction queue or proof of sequence needed for legal work.
Maintain offline or immutable copies and regularly perform a full, timed recovery. Reconciliation procedures should cover transactions submitted immediately before and during the outage.
Plan the manual service
When a national digital system stops, local organisations need an agreed fallback. Define which urgent transactions can proceed, how applications are timestamped, how duplicate submissions are detected and how the backlog will be entered later.
Communicate one authoritative status source. Attackers and fraudsters can exploit an outage with fake payment requests, forged extracts or messages claiming that users must resubmit documents.
Restrict administrative trust
Reporting indicated that valid credentials may have been involved. Privileged access to registry infrastructure should require phishing-resistant authentication, managed devices, just-in-time approval and session recording. Separate backup, virtualisation, directory and application administration so one identity cannot control the entire recovery chain.
A national registry is critical digital infrastructure
The incident’s importance is not measured only by records stolen or servers encrypted. A prolonged loss of authoritative property information can interrupt a country’s economic and legal processes.
Registry resilience must therefore be designed like other critical infrastructure: independent recovery, tested continuity, integrity verification and public communication that restores confidence alongside service.
Official sources and further reading
- ANCPI statement via AGERPRES, 15 July 2026
- Romanian government update via AGERPRES, 27 July 2026
- CERT-EU Cyber Brief, July 2026
Continue the series: European National Cyber & Digital Law Series index



