Decoding the world of cybersecurity

Hungarian Treasury isolates farm systems after attack

Hungary has isolated systems administering agricultural and rural-development funding after a cyberattack encrypted files, while claims of data theft and an exposed WebLogic server remain under investigation.

Hungarian Treasury isolates farm systems after attack
Summary
  • The attack affected the Hungarian State Treasury division responsible for agricultural and rural-development administration.
  • Officials reported encrypted employee files and limited online services but said they had found no loss of customer data.
  • Data-theft claims, the alleged WebLogic entry point, and the attacker’s identity have not been officially confirmed.

Hungary’s State Treasury has isolated systems supporting agricultural and rural-development funding after a cyberattack encrypted files and disrupted some electronic services.

The Treasury said the incident affected the IT network of its Agriculture and Rural Development Division, which acts as Hungary’s national paying agency for agricultural and rural-development funds. Technical staff disconnected affected servers after detecting the attack, while Hungary’s National Cyber Security Centre joined the investigation.

Officials said files on some employee computers were encrypted, indicating the deployment of ransomware or similar malware. Certain online services operated by the division have remained available only on a limited basis while containment and restoration work continues.

The Treasury has said it found no evidence that customer data was compromised or lost. That conclusion does not settle separate allegations that information was copied before encryption, which have emerged through security reporting and material allegedly offered for sale on a criminal forum.

An individual using the name ByteToBreach has claimed responsibility for the intrusion and the theft of government information. The same identity has been associated with a destructive attack against Romania’s land-registry agency, although the Hungarian authorities have not publicly attributed the Treasury incident to that individual.

Hungarian reporting has also identified an unpatched Oracle WebLogic server as a possible initial-access route. The Treasury has not confirmed that account, and no technical incident report has established whether a software vulnerability, stolen credentials, or another route was used.

The distinction is important because WebLogic and comparable enterprise platforms often support administrative systems that cannot be replaced or interrupted easily. Where such software remains reachable from the internet, delayed patching can create a route into processes handling payments, applications, case records, and communications with regulated parties.

The affected division administers programmes connected to Hungarian agriculture and European rural-development funding. A prolonged outage could delay applications, payment decisions, correspondence, or access to records even where the underlying information remains recoverable.

Recovery will therefore require more than decrypting or restoring individual machines. Investigators must determine which identities and systems were reached, whether attackers moved beyond the initially affected servers, and whether restored infrastructure can be trusted before normal access resumes.

The Treasury has notified Hungary’s data protection authority, while law-enforcement and national-security bodies are reported to be examining the case. Authorities have not publicly identified the attacker or confirmed suggestions that the activity originated from infrastructure in Russia. The location of a server would not, by itself, establish who controlled the operation.

The current evidence supports a confirmed cyberattack, file encryption, system isolation, and service limitations. Data exfiltration, the alleged WebLogic route, and the identity of the attacker remain reported claims rather than settled findings.

×