Successful hacking of the national cadastre has brought real estate transactions to a halt – and revealed the poor state of cybersecurity in the country’s major institutions.
Photo illustration: EPA/SASCHA STEINBACH
This summer was supposed to mark an important milestone for Stefania Guga. By the end of July, the 32-year-old had hoped to buy a two-room apartment in a newly built complex on the outskirts of Bucharest, fulfilling her ambition of becoming a homeowner, Guga told BIRN.
“I wanted to finalise the transaction before August 1 to avoid paying the higher VAT rate. But for more than a week now, everything has been at a standstill, and I still don’t know whether I’ll make the deadline. It’s no longer up to me – the problem lies with Romanian state institutions,” she said.
Guga’s plans have been disrupted by a cyberattack on July 14 targeting the IT infrastructure of Romania’s National Agency for Cadastre and Land Registration, ANCPI, effectively freezing property registration services and real estate transactions.
For Guga, the timing could hardly be worse. Under the government’s latest fiscal package, the VAT rate for newly built homes will rise from 9 to 21 per cent on August 1.
If she misses the deadline, it will significantly raise the overall cost of her apartment, adding thousands of euros to the price.
The ANCPI has described the cyberattack as “the most serious technical incident in the institution’s history”.
It crippled the agency’s digital systems, disrupting online land registry services, official email communications and apps used daily by notaries, lawyers, cadastral surveyors and ANCPI staff.
Authorities were left unable to register new property transactions, process pending requests, or issue essential land registry documents, bringing much of Romania’s real estate market to a standstill.
Just one day after the agency’s systems were compromised, some of the stolen data appeared for sale on a well-known hacking forum.
The leaked files included employee login credentials, internal documents and technical information about the agency’s IT infrastructure, raising concerns that the attackers had gained deep access to critical systems.
Experts say that, although the attack did not look particularly sophisticated from a technical standpoint, its consequences are serious.
“This is arguably the most severe cybersecurity incident in Romania’s relatively short history of the digitalisation of public administration,” said cybersecurity expert Andrei Avadanei.
“It affects data belonging to infrastructure classified as critical national infrastructure, including records covering every property in the country.
“It has disrupted essential public services and directly affects hundreds of thousands of citizens whose property transactions and administrative procedures are now vulnerable,” he added.
Avadanei also said the incident could likely have been prevented if the ANCPI had invested more consistently in cybersecurity and implemented stronger preventive measures.
The agency’s spending priorities appear to reinforce that criticism.
According to media reports, ANCPI has invested around 710 million lei, or about 135 million euros, in digitalisation over the past two decades. But only about 0.2 per cent of that, roughly 305,000 euros, was allocated to cybersecurity.
Experts say that figure is woefully inadequate given the sensitivity of the data the agency manages and its role in operating one of the country’s most critical public databases.
Officials have sought to reassure the public and limit the fallout from the cyberattack. In a statement, ANCPI said the incident “did not compromise the agency’s technical or legal databases” and stressed that core land registry records were neither altered nor destroyed.
The agency also said it has begun migrating its applications to the Romanian Government Cloud, a process expected to be completed on Wednesday. Once the migration is finished, specialists will carry out comprehensive integrity checks before services are gradually restored.
At the same time, the incident has exposed the fragility of Romania’s public digital infrastructure at a time when the country is facing a sustained wave of cyber threats linked to the broader security environment created by Russia’s invasion of neighbouring Ukraine.
Romanian authorities and cybersecurity experts have repeatedly warned that government institutions, critical infrastructure and public databases have become attractive targets for hostile cyber actors.
“This incident should serve as a wake-up call for the entire public administration,” interim Digitalisation Minister Irineu Darau said in a televised interview.
Darau acknowledged that the digitalisation of Romania’s public institutions has been carried out in a fragmented way, without a coherent national strategy or common security standards.
“It is time to make digital transformation and cybersecurity genuine national priorities,” he said.
“That also means offering better salaries to cybersecurity professionals working in the public sector so that state institutions can attract and retain the expertise needed to protect critical systems,” he concluded.



