Summary
- The attack disabled e-Terra and other central services used to complete property transactions across Romania.
- Authorities say core ownership, boundary, and mortgage records were not compromised, although limited exfiltration remains possible.
- Restoring an authoritative public register requires evidence that its records were neither altered nor silently corrupted.
Romania’s National Agency for Cadastre and Land Registration is restoring digital services after a cyberattack interrupted property sales, mortgage processing, and access to official land records across the country.
The disruption affected e-Terra, the national cadastral and land registration platform used by notaries, lawyers, cadastral specialists, lenders, and public authorities. Official email and other applications running on the agency’s central infrastructure were also taken offline, leaving property professionals unable to request extracts, register transactions, or complete work that depends on authoritative ownership and mortgage information.
ANCPI has said that its core technical and legal databases were not compromised. Those systems contain the records that establish property boundaries, ownership, mortgages, and other legal interests, making their integrity more consequential than the temporary availability of the public services built around them.
Romanian cyber officials said the attackers used known vulnerabilities and credentials that had previously been exposed. Investigators had not found evidence that personal data or land certificates were stolen, although a limited quantity of credentials and source code may have been obtained. Claims that wider databases were destroyed or extracted have not been verified and conflict with the agency’s public account.
Recovery has involved isolating the affected infrastructure, correcting identified weaknesses, and moving applications towards Romania’s government cloud while integrity checks continue. Services have been returned in stages so that recovered applications and records can be validated before users regain access.
A nationally authoritative register carries a different recovery burden from an ordinary business application. Restoring a server and making a service available does not establish that ownership records, legal restrictions, boundary information, and transaction histories remain trustworthy. An availability failure delays commerce, whereas an integrity failure could create disputes over the legal basis of property ownership and lending.
Backups remain essential, although they do not resolve that assurance problem by themselves. Recovery teams need to establish when the attackers first gained access, which administrative accounts were used, what interfaces or databases were reached, and whether the selected backup predates the intrusion. Where credentials or source code may have been taken, rebuilding the same application without rotating secrets and closing the original access path risks preserving the attacker’s route back into the environment.
The outage also exposed the number of external processes dependent on a single public platform. Property sales, lending decisions, tax activity, legal filings, and construction projects can all be delayed when cadastral services are unavailable. Continuity planning therefore extends beyond ANCPI, because notaries, banks, local authorities, and property businesses also need procedures for periods when the central register cannot be reached.
Romania has been expanding shared government infrastructure and cloud services, which can improve monitoring, standardisation, and recovery when migration is supported by clear technical ownership and tested operational controls. Centralisation also concentrates dependency, requiring public bodies to identify which services would interrupt essential economic or administrative activity if they failed.
ANCPI has asked users to rely on official updates while forensic work continues. The remaining investigation will need to establish the length of the intrusion, the material taken from the environment, and whether the changes introduced during recovery remove the weaknesses that allowed the attackers to enter.




