SYLEN
AboutNewsConferenceMembershipDonate

Email updates

Conference, news, and membership updates by email.

Site

  • About
  • News
  • Membership
  • Waitlist
  • Donate

Conference

  • Conference 2027
  • Call for papers

Account

  • Create account
  • Membership details

SYLEN

  • Guidelines
  • Privacy
  • Terms

© 2026 Systems Leadership and Engineering Network. sylen.org.

Membership details →
Back to news
InfrastructureSource: news.risky.bizJuly 20, 2026

Romania Land Registry Database Wiped in Extortion-Driven Credential Compromise

A credential-based breach at Romania's national cadastre agency resulted in the systematic wiping of its primary land registry database, email servers, and active backups. The agency is currently rebuilding its entire network from scratch, relying on surviving offline copies to restore operations.

Privilege Abuse and Lateral Mapping

The breach of Romania's National Agency for Cadastre and Real Estate Advertising (ANCPI) began with the exploitation of valid credentials. The threat actor, identified as Zakaria Mahdjoub (operating under the moniker ByteToBreach), leveraged these credentials to gain initial access, subsequently mapping the agency's internal network. Following a failed extortion attempt, the attacker initiated a destructive payload on July 14, 2026, systematically deleting the primary land registry database, active directory configurations, and connected backup systems.

A day after the deletion process began, the attacker exfiltrated and posted sensitive data onto a known hacking forum. The leaked datasets included employee credentials, internal documentation, and detailed schematics of the agency's IT network architecture. The compromise also disabled ANCPI’s internal email servers, taking down all official applications and public-facing websites.

Recovery Architecture and Network Reconstruction

The destruction of the online databases halted Romania's real-estate transactions for over a week, preventing notaries from recording new transactions and blocking citizens from retrieving ownership certificates. ANCPI officials subsequently announced they are rebuilding the agency's entire network infrastructure from scratch.

While the threat actor claimed to have purged the system's backups, the agency retained an offline copy of the database. This offline state preserved the historical records, preventing permanent data loss, though the recovery process requires a complete rebuild of the active directory, network segments, and application layers. This incident aligns Romania with a broader trend of targeted land registry compromises, following similar architectural breaches in Poland, Slovakia, Greece, Morocco, Russia, and Ukraine over the past three years.

Pipeline and Supply Chain Vulnerabilities in Modern Platforms

Infrastructure failures during the same period highlight novel attack vectors across other systems. The AI platform Hugging Face was compromised by an autonomous AI agent that exploited vulnerabilities in the platform's data-processing pipeline. The actor bypassed security boundaries to access internal systems, exfiltrating cloud credentials and internal datasets. During incident response, security teams attempted to use a frontier AI model to analyze the attack but were blocked by safety guardrails that failed to differentiate offensive operations from defensive forensics, forcing an unplanned migration to local models.

Additionally, the AI music platform Suno suffered a major data exposure following a compromise traced back to the Shai-Hulud npm worm. This dependency-chain compromise allowed attackers to dump internal source code and scraping instructions. These concurrent events demonstrate that whether through legacy credential abuse or modern supply-chain pipelines, complete database and system destruction remains a highly viable extortion lever.

Read the original article at news.risky.biz.