HotInfo Menu
✍️ EDITORIAL PICKS
Hackers strike Romanian state for the second time in two weeks: after the land registry, they now lock down prisons

Hackers strike Romanian state for the second time in two weeks: after the land registry, they now lock down prisons

On Wednesday, the Romanian National Administration of Penitentiaries (ANP) suspended transfers of prisoners between facilities and moved the nearest court hearings to videoconference following a ransomware attack that knocked out prisoner telephone calls, the visitation portal, and the connection between individual facilities. This is already the second serious cyberattack on a key state institution in two weeks — on July 14, an attacker encrypted and deleted part of the IT infrastructure of the Romanian land registry, including part of its backups, freezing the real estate market for weeks to come. Both cases now raise an uncomfortable question about what the contracts worth nearly 2.5 billion lei (about 500 million euros), which according to an analysis by the daily Ziarul Financiar the Romanian intelligence service SRI signed for cybersecurity over the past year and a half, were actually used for.
Key actors — tap for context

Prisons on restricted regime

On Wednesday morning, the National Administration of Penitentiaries (ANP) detected an attack on "multiple workstations and servers" — affected were the IMS Web platform, information kiosks in prisons, the visit-scheduling portal, and the VPN connection between individual facilities. HotNews.ro ↗

ANP's IT team immediately contacted the National Directorate for Cybersecurity (DNSC), which physically disconnected the affected devices from the network to prevent the ransomware from spreading. ANP director Geo-Bogdan Burcu reassured the public: "It is estimated that the damage will be minimal, since most of the data has a backup." At the same time, he admitted that investigators do not yet have a suspect: "At present we have no indication of who [caused the attack] or why." The institution announced it would file a criminal complaint with the DIICOT prosecutor's office, which handles organized crime. Digi24 ↗

Until the systems are restored, transfers of prisoners between facilities are suspended and handled only exceptionally and on a case-by-case basis, while court hearings are taking place via videoconference. Prisoner phone calls have been limited to five minutes a day and only to previously approved numbers, arranging visits and purchases at prison canteens now goes exclusively by phone or in person through staff, and all submissions must be handed in by prisoners in paper form. Pro TV ↗

The land registry, now in its third week of crisis

The attack on the prisons is not an isolated case. About two weeks earlier, on July 14, someone using the alias ByteToBreach broke into the systems of the National Agency for Cadastre and Land Registration (ANCPI) — according to security sources via stolen legitimate login credentials and a poorly protected entry point, though the exact method of intrusion is still under investigation. After the agency refused to give in to extortion, the attacker, according to their own statements and security analysts, encrypted and then deleted part of the virtualization infrastructure, including part of the backups, and published stolen employee login credentials as well as internal documents on a hacker forum. IANS Research ↗

Ordinary people and notaries alike felt the consequences — without land registry extracts and cadastral maps, no real estate transfers could be carried out for three days, mortgages stalled, and deposits for apartment purchases remained frozen. The Romanian government subsequently clarified that the damaged components were the virtualization infrastructure and the e-Terra application, but that the central cadastral database and the register of ownership relations to land were not damaged, and it has no evidence that the attacker gained access to them. Nevertheless, the government still cannot say when the system will be fully restored. Digi24 ↗

The security firm KELA identified the attacker — with medium confidence based on forum activity and open sources, not an official investigation — as someone likely operating from the Algerian city of Oran, though Romanian authorities have not officially confirmed the identity. ByteToBreach personally told journalists that the motive was financial gain, and apologized to the Romanian public for the problems caused. Euronews Romania ↗

Where half a billion euros went

Both attacks highlight an uncomfortable question about Romania's cybersecurity spending. According to an analysis by the daily Ziarul Financiar, the Romanian civilian intelligence service SRI signed cybersecurity contracts worth more than 2.5 billion lei — roughly 500 million euros — between January 2025 and July 2026 alone. The Special Telecommunications Service (STS) received contracts for the same purpose worth about 51 million lei — and DNSC itself, the authority that actually intervened in both attacks, received only about half a million lei. Ziarul Financiar ↗

Adrian Munteanu, a university professor and DNSC-certified security auditor, therefore warns that the problem is not a lack of money, but where it was spent: "Romania does not need more paperwork. It needs cyber risk to have concrete consequences for budgets, projects, and management careers." Instead of yet more new offices and certificates, he is calling for more practical rules and strengthened powers for DNSC — the institution that actually did the fieldwork in both attacks, yet received only a fraction of the budget of the other agencies. Ziarul Financiar ↗

Romania is, moreover, a member of both the EU and NATO, and its land registry and prison system hold sensitive personal data on millions of people. Two successful attacks on critical state infrastructure within two weeks can therefore not be dismissed as bad luck — they point to a pattern that could repeat at the next institution, unless there is a change in who actually decides where the money goes within the cybersecurity system.

What hotinfo is following

  • The outcome of the DIICOT investigation into the attack on ANP — the attacker's identity and motive
  • The date when ANCPI will restore full functionality of the land registry system (no date yet)
  • Whether the Romanian parliament or government will respond to criticism of the disparity between the SRI and DNSC budgets
  • Whether the pattern will repeat at another state institution (healthcare, tax administration, civil registry)
  • Any official confirmation of ByteToBreach's identity by Romanian authorities

World Technology Economy & Business 🏢 administrația națională a penitenciarelor 🏢 agenția națională de cadastru 🏢 agenția națională de cadastru și publicitate imobiliară 🏢 directoratul național de securitate cibernetică 🏢 național de securitate cibernetică 🏢 român de informații 🏢 rumunská väzenská správa 🏢 serviciul român de informații