Romania's cadastre agency said on Monday that the land registry data at the centre of last week's destructive cyberattack was never lost. ANCPI, the National Agency for Cadastre and Land Registration, stated that its technical and legal databases were not affected by the July 14 incident, and that backup copies were held in several separate designated locations. That directly contradicts the headline that travelled the world for six days: that a hacker had wiped an entire country's property records.
- The agency's claim is narrow and specific. ANCPI says the technical and legal databases survived and that redundant backups existed in multiple locations by design.
- The attacker never needed a vulnerability. Entry was made with valid credentials, then the intruder mapped the internal network before destroying systems.
- Recovery is an infrastructure problem, not a data problem. ANCPI is migrating its applications into Romania's Government Cloud with the Special Telecommunications Service, targeting July 22.
- There is still no restoration date for the public. Notaries and citizens have been locked out for roughly a week, and the agency has not said when e-Terra comes back.
What actually happened on July 14?
The attack against ANCPI became public on July 14, 2026, when the agency's services dropped offline. The intruder did not break in through an unpatched product. According to reporting on the incident, the attacker signed in with valid credentials, carried out internal reconnaissance to map the agency's systems, and then began destroying them after an extortion attempt failed.
RelatedServiceNow's CVSS 9.5 Sandbox Escape Is Now Exploited
The blast radius covered ANCPI's production environment: the e-Terra land registry platform, the agency's public websites and official applications, and its email servers. On July 15 the attacker, operating under the alias ByteToBreach, listed stolen material for sale on a hacking forum. The listing advertised employee credentials, internal documents, and details of the agency's IT network. Threat intelligence firm KELA associates that alias with Zakaria Mahdjoub, based in Oran, Algeria. The attacker also publicly claimed to have deleted backup copies specifically to prevent recovery.
Why do the hacker's claim and the agency's claim both fit?
These two statements look contradictory but can both be true, and understanding why is the most useful thing to take from this incident. An attacker inside a production network can genuinely delete every backup they can see. Backup repositories mounted as network shares, connected backup appliances, and snapshots managed from the same domain are all reachable with sufficient privilege, and wiping them is standard practice before extortion. So the attacker's boast about destroying backups is plausible for the copies within reach.
What that does not cover is any copy held outside that blast radius. ANCPI's statement is precise on this point: it says the agency had several locations designated for storing backup copies, described as a redundancy measure intended to make restoration possible during exactly this kind of incident. If a copy sat offline or in an environment the compromised credentials did not govern, the attacker never touched it and would have no way of knowing it existed.
This is why the phrase "wiped the entire database" was doing a lot of work in the coverage. The production database really was destroyed. Whether the country's property records were destroyed is a separate question, and the agency's answer is no.
How the story developed
- Jul 14Attack goes public as ANCPI services drop offline Entry via valid credentials, systems destroyed after failed extortion
- Jul 15Stolen data listed for sale on a hacking forum Employee credentials, internal documents, IT network detail
- Jul 14 to 20Property market stalls nationwide Notaries cannot register transactions, citizens cannot obtain ownership proof
- Jul 20ANCPI says technical and legal databases were not affected Confirms backup copies in several separate locations
- Jul 22Target date to finish Government Cloud migration Coordinated by the Special Telecommunications Service
Who is actually affected right now?
The people paying for this are not reading threat intelligence reports. For roughly a week, Romanian notaries have been unable to record new property transactions, because registration in the land book is what makes a transfer legally effective. Citizens have been unable to obtain proof of ownership or detailed land records, documents that mortgage approvals, court filings, inheritance procedures and sales all depend on. A national property market does not have a manual fallback for this. It simply stops.
That is the part the agency's reassurance does not fix. Confirming the data exists somewhere is meaningful for the long term and does nothing for a sale scheduled this week. ANCPI has been explicit that it is not yet able to say when applications will be available again, and that service will return in stages according to operational priority rather than all at once.
RelatedAssuranceAmerica Breach Hit 6.9M Driver's Licenses
What does the Government Cloud migration change?
ANCPI is not rebuilding what it had. It has begun moving its applications into Romania's Government Cloud, with the migration coordinated by the Special Telecommunications Service, known as STS, and estimated to complete on July 22. Once that finishes, authorized institutions are to verify the applications and data and produce a report on the state of the systems plus any further measures required. Only after that report will ANCPI be able to give a restoration estimate.
Read that sequence carefully, because it explains the timeline better than any statement about data loss. The bottleneck is not recovering records. It is standing up a trustworthy environment to put them in and then proving it is clean. An agency that was breached through valid credentials cannot restore into the same infrastructure and credibly claim the intruder is gone. The rebuild is the slow part, and it is the correct part.
- The verification report. Its conclusions, not the July 22 migration date, will determine when e-Terra actually returns.
- Restoration completeness. Watch whether records created in the days before July 14 survive, since backup freshness is where offline copies usually lose.
- Credential provenance. Nobody has explained how valid credentials were obtained. Infostealer logs and unmanaged contractor accounts are the usual answers.
- The stolen data. Destruction was reversible here. The exfiltrated employee credentials and network documentation are not, and they outlive the outage.
Our take
The reassuring headline and the alarming one are describing different assets, and the industry keeps conflating them. ANCPI appears to have gotten one thing right that a great many organisations get wrong: it kept restorable copies outside the reach of the credentials that ran its production estate. That single design choice is the difference between a national land registry that comes back and one that does not.
It also got something badly wrong, and the fix is not glamorous. An intruder with valid credentials mapped an entire national agency's internal network and then destroyed production, which means privilege boundaries and detection both failed well before anything was deleted. Backups determined whether Romania lost its property records. They did nothing to prevent the week the country has already spent unable to buy or sell property, and no cloud migration retroactively buys that week back.
- OfficialANCPI , National Agency for Cadastre and Land Registration, agency statements and service status
- ReferenceEuronews Romania , July 20 statement that technical and legal databases were not affected
- SecurityRisky Business News , attack chain, credential-based entry and the forum listing
- SecurityHelp Net Security , incident timeline and data-for-sale claims
Original analysis by GenZTech. Reporting sourced from Risky Business News and ANCPI's July 20 statement.
