Assessment updated 18 August 2026

The breach opened
nearly all of ANCPI's infrastructure.

DNSC’s interim technical analysis confirms double-extortion ransomware, extensive network compromise, extracted user data and about 100 deleted virtual machines. It identified no access to the central Oracle Exadata cadastral database.

How to read the evidence

DNSC cross-checked logs and command histories against screenshots published by the attacker. Official findings are separated here from the attacker’s estimates and what remains unknown. Personal data, passwords, IP addresses and account names have been removed from the reproduced images.

What the evidence supports

What the attacker probably obtained

DNSC’s 22 July report moves a substantial part of the assessment from attacker-attributed screenshots into official findings.

High confidence

Source code for e‑Terra and related services

DNSC confirms access to and repositories containing , ePayment and projects. The report describes significant exposure of source code for critical components.

High confidence

Credentials, configurations and the infrastructure map

, , a , , and expose servers, county offices, trust relationships and privileged accounts. Veeam, FortiSIEM and the NOC tool appear to contain login details for virtualisation, hosts, storage and network equipment. In OpenDJ, the attacker appears to decrypt at least one stored password value using a key recovered from the compromised environment.

Confirmed by DNSC

A large user directory

DNSC concludes that the attacker directly queried and extracted records containing names, email addresses, identifiers and password hashes. The report says the data appears to belong to external application users. The estimate of about two million comes from the attacker and is not validated as a total count.

Confirmed by DNSC

Administrative control of virtualisation and backups

DNSC confirms administrative access to vCenter, an inventory of 1,083 virtual machines and the deletion of about 100. Command history also confirms the external transfer of a virtual disk belonging to an Active Directory domain controller. ANCPI’s team says Veeam backups for test machines were deleted, while the report separately records deleted copies visible in the attacker’s screenshots.

Unconfirmed for the central database

Cadastral data and e‑Terra documents

DNSC says the published screenshots do not show access to Oracle Exadata, the database holding the most important ANCPI application data, and considers it highly unlikely that the attacker holds data from it. ANCPI’s team reported that the database still answered queries before a precautionary shutdown and that a replica in Brașov was updated every four hours. Theft of the national cadastral register remains unproven.

Why the screenshots look coherent

The screenshots describe a path through the infrastructure.

Each stage explains access to the next. That does not automatically authenticate the images, but it is harder to fabricate convincingly than one spectacular screenshot.

Entry


A legacy identity service appears compromised, providing server execution.

Identities

/
The directory returns accounts and password fields; a key appears to decrypt some secrets.

Pivoting

/
Internal application servers provide further execution points and internal-network reach.

Knowledge

/ /
Code explains the applications; monitoring explains the topology and where high-value targets sit.

Control

/
Virtualisation and backup are the points from which whole systems can be copied, stopped, encrypted or deleted.

Domain


The screenshot shows administrator and privilege-relationship enumeration, but the attacker says full takeover was not completed.

Evidence atlas

What each screenshot family shows

Images are reproduced only in heavily redacted form. The explanation preserves the public-interest value of the evidence without republishing passwords, accounts or personal data.

Redacted screenshot representing initial access through an identity service
01

The entry point looks real and predates the outage

The screenshot shows a shell on an OpenAM server and a 10 July timeline. A shell does not automatically mean access to all data, but it provides an internal point from which lateral movement can begin.

Supports
initial compromise and persistence
Does not prove
cadastral-database exfiltration
Redacted screenshot representing the OpenDJ user directory
02

The identity directory appears directly queried

LDAP records with names, emails and password fields are visible. In a separate panel, the attacker appears to test a key used to decrypt some secrets. The “two million” figure remains the attacker’s estimate.

Supports
theft of or access to account data
Does not prove
that every password was recovered
Redacted screenshot representing ANCPI source-code projects
03

The code structure fits a real institutional platform

The project tree includes e‑Terra components, payments, reports, security, single sign-on, APIs, validation and GIS. Java package names use the ANCPI domain. Together, these details make the GitLab claim highly credible.

Supports
copying code and development history
Secondary risk
secrets in configurations or old commits
Redacted screenshot representing vSphere and Veeam
04

DNSC identifies 1,083 virtual machines and about 100 deletions

The report confirms the administrative vCenter session and an inventory of 1,083 virtual machines. ANCPI initially estimated that about 100 of 700 had been deleted; later analysis established the larger inventory. In Veeam, screenshots show completed deletion operations.

Supports
administrative control over a very large infrastructure and successful Veeam deletions
Does not prove
that all 1,083 machines or all backups were copied or destroyed
Redacted screenshot representing the Active Directory structure
05

Active Directory was mapped, while domain-controller files were within reach

BloodHound shows administrators and thousands of control relationships; the selected account is assigned local rights on 171 systems and control over 10,978 objects. In vSphere, the virtual-machine directories for domain controllers and Download, Copy and Delete actions are visible. DNSC later confirms from command history that the “DC1” controller’s virtual disk was transferred to an attacker-controlled server.

Supports
privilege mapping and the ability to reach domain-controller VM files
Evidence limit
the disk transfer is confirmed; full Domain Admin control is not demonstrated
What appears under magnification

The details in the screenshots show how wide the potential control radius was.

These figures first appeared in interfaces displayed by the attacker. DNSC later corroborated the main path using logs, command histories and technical artefacts, and corrected some values — including the virtual-machine inventory. Unconfirmed volumes remain labelled separately. The figures describe access and capability; they do not automatically prove that every system was copied or destroyed.

vCenter1,083

virtual machines inventoried in the infrastructure

DNSC confirms that the attacker extracted vCenter data for 1,083 virtual machines and used the platform for lateral movement, enumeration and datastore access. The report’s figure supersedes the 1,071 visible in the screenshot first reviewed.

Status: confirmed in DNSC’s technical analysis.
OpenDJ / OpenAM1

encryption key used to recover readable passwords

DNSC confirms that the attacker obtained the application’s encryption key through a component installed in OpenAM and used it to recover readable administrative credentials. These opened access to the OpenDJ directory and its user database. The report does not establish how many passwords were recovered in readable form.

Status: mechanism confirmed by DNSC; the wider scale remains unknown.
Patch management2021 → 2026

two public code-execution routes almost five years old

The tools displayed point to CVE-2021-35464 against OpenAM and CVE-2021-22205 against GitLab. Both are critical remote-code-execution vulnerabilities whose fixes were public in 2021. The screenshots do not explain why the systems remained vulnerable or whether compensating controls existed.

Corroboration: NVD/CISA and official GitLab documentation.
VeeamSUCCESS

deleted backups, separate Oracle replica retained

DNSC records ANCPI’s explanation that the deleted Veeam backups belonged to test machines. The attacker’s screenshots also show deleted copies for GitLab, accounting, GeoServer and Active Directory. Oracle Exadata had a replica in the Brașov data centre, updated every four hours.

Status: deletions confirmed; total backup destruction is contradicted by the separate replica.
Active Directory171 / 10,978

one account with a very wide privilege radius

The panel assigns the selected account local-administrator rights on 171 systems and outbound control over 10,978 objects; it also shows 17 group memberships and two execution privileges. These are relationships calculated by the tool, not proof that every path was exploited.

Status: privilege mapping; complete domain takeover is not shown.
Domain controller2012 R2 + SMBv1

a legacy component at the centre of the network

A scan displayed by the attacker identifies a domain controller as Windows Server 2012 R2, with enabled and reported by the tool. Windows Server 2012 R2 was outside standard support, although could run until October 2026; Microsoft strongly recommends removing SMBv1. The screenshot alone does not prove that this configuration was exploited.

Status: attacker-screenshot identification, contextualised with Microsoft documentation.
Control over control

An Active Directory controller disk was transferred externally

Command history reviewed by DNSC contains the operation that copied the “DC1” controller’s virtual disk to an attacker-controlled server. This confirms the virtual-machine transfer. The report distinguishes that disk transfer from full Domain Admin control, which the attacker said had not been completed.

Two screenshots published by the attacker

Access appears to have spread easily across offices and systems.

county office Aadministrator[same password]
county office Badministrator[same password]
county office Cadministrator[same password]

A generic credential repeated across offices

One screenshot attributed to the attacker appears to show equipment associated with several county offices using the same account and trivial password. If authentic, compromise of that account could open many offices at once.

virtual platformprivileged administrator[weak human-made password]
applicationsvirtual machinesbackup

A privileged account protected by a name-derived password

Another screenshot attributed to the attacker appears to show credentials for a vSphere administrative account. This is the data centre’s electrical panel: a weak password here can turn a local breach into a nationwide shutdown.

What appears to have failed

Six barriers that should have stopped the path

DNSC’s interim report identifies unpatched services, near-absent segmentation, password reuse and insufficient logging as structural weaknesses that enabled the attack to spread.

01

Failed patch management

DNSC links initial access to a critical OpenAM vulnerability and confirms exploitation of an unpatched GitLab instance through vulnerabilities known since 2021.

02

Shared, weak passwords

DNSC confirms password reuse across systems and equipment. A password recovered from GitLab also worked in Kerberos, accelerating the spread of access.

03

Management tools became password vaults

DNSC confirms that credentials for numerous network devices were extracted from FortiSIEM, stored with reversible encryption and reused across different locations.

04

Insufficient segmentation

The report describes internal segmentation as nearly absent: a compromised production server could communicate directly with the vCenter management plane.

05

Recovery sat inside the same trust domain

An attacker inside the infrastructure appears able to administer and delete the very copies used to rebuild the systems.

06

Excessively concentrated privilege

A single account appears to have local rights on 171 systems, while vSphere control could expose even the disks of domain controllers.

The correct limits of the conclusion

What cannot yet be said

Not publicly demonstrated

  • that the complete database of nearly 29 million properties was extracted;
  • that “the data of all Romanian citizens” is included;
  • how many virtual machines, backups or databases were copied;
  • whether passwords seen in the screenshots remained active after the incident;
  • whether the attacker obtained full Domain Admin control.
  • that archives circulating online are authentic, complete and unchanged.

“We have no indication that they were accessed. The citizens’ databases are on servers the hackers did not access.”

Laurențiu-Alexandru Blaga, ANCPI director general, speaking to G4Media, 17 July 2026

DNSC’s 22 July analysis and the Government’s 27 July statement support this separation. DNSC identified no access to Oracle Exadata, while the Government says the central database was unaffected and that the integrity of cadastre and land-register records has been confirmed.

This finding concerns the central cadastral database. DNSC separately confirms the extraction of OpenDJ records, while the Government says the investigation must establish whether and to what extent ePay user data was affected.

Current status · 18 August

What remains valid after all updates

Successive statements are consolidated here by subject rather than stacked in publication order. The full timeline and dated sources remain below.

22.07
Technical finding

Extensive compromise, with no identified access to Oracle Exadata

DNSC confirms double-extortion ransomware, access to most devices, extracted OpenDJ data, exposed source code and passwords, about 100 deleted virtual machines and the transfer of an Active Directory controller disk. The report considers it highly unlikely that the attacker holds data from the central cadastral database.

27.07
Users

ePay risk remains separate from the integrity of the cadastral database

Romania’s Government confirmed the integrity of cadastral records but kept open the investigation into possible effects on ePay user data. Its official advice is to change ePay passwords, especially if reused, and to be cautious about messages or calls requesting data or access codes.

gov.ro · 27.07 ↗
11–17.08
Phased recovery

e‑Terra is operating; about 100,000 requests were resolved in one week

e‑Terra restarted in stages on 11–12 August. According to an ANCPI document reviewed by Profit.ro, about 100,000 requests were resolved between 11 and 17 August, while 165,146 were registered between 11 and 14 August. The periods differ, so the figures do not form a resolution rate.

The restart still covers only e‑Terra. RTI, MyEterra, the Owners Register, Property Titles and Geoportal remain unavailable and are due to restart in stages. Card payment is available where the service and workflow allow it.

04.08
Public consequence

Law 161/2026 is published; it enters into force on 7 August

Law 161/2026 was published in the Official Gazette on 4 August and enters into force on 7 August. For eligible transactions completed at 21% VAT between 1 and 6 August, there is a route to claim reimbursement; the next open element is the procedure ANAF must approve within 30 days.

What the attacker interviews add

Financial motivation becomes more plausible; the conflict over the main databases becomes explicit.

ByteToBreach tells Euronews that the data is not sold “to just anybody” and disputes the €10 million figure, but says such matters are discussed with “the relevant parties”. Separately, the DNSC director describes a non-state, financially motivated actor, suspected to be Algerian and specialised in initial access, exfiltration and extortion. The assessment is preliminary, while the attacker says he acts alone.

In an interview published by SecurityPatch, ByteToBreach claims to have encrypted numerous files, exfiltrated but not encrypted the main databases, and left a ransomware note while making decryption assistance negotiable. The claim about the main databases directly contradicts the ANCPI director’s account. The interview publishes no new evidence for these statements.

What should be disclosed publicly

Five important questions remain

  1. 01

    How many OpenDJ records were extracted, and exactly which categories of people are affected?

  2. 02

    Which other virtual machines, disks or backups were transferred externally beyond the “DC1” controller disk?

  3. 03

    ANCPI says its remediation plan includes changing administrative credentials and security keys. Has the rotation of all passwords, certificates, API keys and secrets in Git history been completed?

  4. 04

    ANCPI says identified backups are being used for restoration. Which offline or immutable copies survived, what period do they cover, and what will the final report confirm about their effectiveness?

  5. 05

    Will the final investigation findings be published, including the number of people affected and the corrective measures taken?

Incident timeline

From initial access to the e‑Terra rebuild

The screenshots place attacker activity before the shutdown; later statements and reporting document the investigation, rebuild and operational recovery through 17 August.

The OpenAM screenshot indicates an initial shell.

Pivots appear toward application servers, GitLab, Zabbix and other internal systems.

Screenshots show vSphere, Veeam, credentials and Active Directory collection.

ANCPI shuts down or loses access to all managed systems, including email and e‑Terra.

The institution confirms the attack and calls it the largest technical disruption in its history.

ANCPI’s director general tells G4Media that the institution has no indication that personal data was accessed or extracted and says the citizens’ databases were on servers the attackers did not reach. He says property transactions cannot be completed until the applications restart and identifies 20 July as a target, without guaranteeing it.

Media reports that material attributed to ANCPI is being offered for sale. HotNews, citing a source familiar with the incident, says authorities are investigating a possible ransom demand. Neither the scope of the data nor the demand has been officially confirmed.

In a text interview with Euronews Romania, ByteToBreach apologises for the disruption, says the motive is financial and speaks about selling the data. The attacker disputes the €10 million figure without ruling out discussions with the parties involved.

DNSC director Dan Cîmpean says the available information points to a non-state, financially motivated actor, suspected to be Algerian and specialised in initial access, exfiltration and extortion. In the same report, ByteToBreach says it is not a group.

ANCPI announces infrastructure reinstallation and hardening, backups in multiple locations and a phased service restart. The institution says investigations continue and that it cannot yet communicate an official conclusion on the matters under investigation; services remain unavailable.

ANCPI says its technical and legal databases were not affected and announces an STS-coordinated migration of applications to Romania’s Government Cloud. Migration is expected to finish on 22 July; subsequent checks and a technical report will precede any estimated date for restarting the applications.

DNSC publishes its interim technical analysis, confirming double-extortion ransomware, extensive infrastructure compromise, extracted OpenDJ data, 1,083 inventoried virtual machines and about 100 deletions. It identifies no access to Oracle Exadata.

Romania’s Government confirms the integrity of the central cadastral database and says e‑Terra is being rebuilt directly in the Government Cloud. It gives no firm restart date, advises ePay users to change their passwords and says the investigation into any impact on their data remains open.

Romania’s Government announces completion of the infrastructure rebuild and e‑Terra’s migration to the Government Cloud. The application remains unavailable to users during final independent testing by DNSC, STS and Cyberint; no reopening date is announced.

After promulgation, Law 161/2026 is published in the Official Gazette, Part I, no. 642. It enters into force on 7 August. Eligible transactions taxed at 21% between 1 and 6 August have a route to reimbursement, while ANAF’s procedure remains to be approved within 30 days.

ANCPI restarts e‑Terra in stages. A document reviewed by Profit.ro records about 100,000 requests resolved between 11 and 17 August and 165,146 registered between 11 and 14 August; the periods do not allow a resolution rate to be calculated. RTI, MyEterra, the Owners Register, Property Titles and Geoportal remain unavailable.

Methodology

How attacker-produced evidence connects to the official analysis

Technical specificity

Product names, project structures, topologies, hostnames and privilege relationships that match across screenshots.

Temporal coherence

Activity displayed from 10 to 13 July predates the general outage announced on 14 July.

Causal coherence

Identity access explains application access; monitoring reveals targets; virtualisation and backup explain the scale of the shutdown.

Forensic corroboration

DNSC compared the screenshots with logs, command histories and artefacts collected from vCenter and ESXi servers. The report confirms the main path, including initial access, lateral movement, ransomware, deletions and a virtual-disk transfer.

Circulation is not verification

User counts, exfiltrated volume, claims of completeness and the authenticity of redistributed archives are not accepted without independent corroboration or forensic confirmation.

Harm minimisation

Data archives were not opened. Download links, passwords, personal addresses, accounts and details that could facilitate access are not republished.

Sources and status

What is official, what is analysis, what is a claim

Official / technical analysis

DNSC — interim technical analysis, 22 July

Confirms double-extortion ransomware, extensive access, compromised OpenDJ data, exposed source code, 1,083 inventoried virtual machines, about 100 deletions and the transfer of an Active Directory controller disk. It identifies no access to Oracle Exadata.

Download the DNSC analysis (PDF, 28 pages) ↗
Document publication

InPolitics — PDF publication, 24 July

InPolitics made public the DNSC technical annex used here. A copy is retained on this site for stable access; this assessment relies on the DNSC document, not on the article’s editorial interpretation.

InPolitics ↗
Official / operational update

Romanian Government, 27 July

At that date, it confirmed the integrity of the central cadastral database, described e‑Terra’s reconstruction in the Government Cloud and gave no firm restart date. It advised ePay users to change their passwords and announced network segmentation, multi-factor authentication for privileged accounts and continuous monitoring.

gov.ro ↗
Official / operational update

Romanian Government, 30 July

Announces completion of the infrastructure rebuild and e‑Terra’s migration to the Government Cloud. The application is installed but remains unavailable during final independent validation; no reopening date is given.

gov.ro ↗
Official / operational update

ANCPI — phased restart, 11 August

Announces the phased restart of e‑Terra for successive user groups, continued downtime for other public platforms, about 94,000 pending requests and preservation of the date, time and rank of filings made during the outage.

ancpi.ro ↗
Reporting / ANCPI document

Profit.ro — technical and operational status, 18 August

Reports, based on an ANCPI document reviewed by the publication, that backups are being used for restoration, that no signs of compromise were found in electronic-document storage, and describes remediation measures and e‑Terra’s operational recovery. The document is not the final report and is not published in full.

Profit.ro ↗
Official

ANCPI — statement of 15 July

Confirms the attack, outage of all systems including email and e‑Terra, and states that data was not compromised.

ancpi.ro ↗
Official / update

ANCPI — 19 July post

On 19 July, it confirmed infrastructure reinstallation and hardening, backups in multiple locations, plans for a phased restart and that services were unavailable. It said investigations were continuing and that no official conclusion could yet be communicated on the matters under investigation.

Facebook / ANCPI ↗
Official / update

ANCPI — 20 July post

On 20 July, it said the technical and legal databases had not been affected and announced an STS-coordinated migration of applications to Romania’s Government Cloud. The estimate at the time placed completion on 22 July, before checks and any restart date would be set.

Facebook / ANCPI ↗
Official

ANCPI — system scale

The homepage reported 28,977,942 managed properties on 13 July 2026.

ancpi.ro ↗
External analysis

KELA — profil ByteToBreach

Describes an operator with real technical activity and often credible claims, but also aggressive marketing and self-promotion.

kelacyber.com ↗
Reporting

Public Record / HotNews / Help Net Security / Profit.ro

They report the sale offer and claims concerning data and source code. HotNews adds, based on an unnamed source familiar with the incident, that authorities are investigating a possible ransom demand. This is not official confirmation.

Interview

G4Media: interview with ANCPI’s director general

Laurențiu-Alexandru Blaga says the citizens’ databases were neither accessed nor extracted, that property transactions are blocked while the applications remain offline, and that their restart is targeted for 20 July. The date is presented as a goal, not a firm commitment.

g4media.ro ↗
Interviews / hostile source

Euronews and SecurityPatch: ByteToBreach

Euronews records the financial motive and DNSC’s preliminary assessment. SecurityPatch publishes further claims about file encryption, exfiltration of the main databases, a ransom note and negotiable decryption assistance. The attacker’s statements are not independent evidence and, regarding the main databases, contradict ANCPI’s account.

Consequence / published law

Presidency and Legislative Portal / Law 161/2026

On 4 August, the law is both promulgated and published in the Official Gazette, Part I, no. 642. It enters into force on 7 August. Eligible transactions completed at 21% VAT between 1 and 6 August may claim the VAT difference from 1 October; ANAF must approve the procedure within 30 days of entry into force.

Hostile claim

Screenshot set attributed to the attacker

Twelve images concerning OpenAM, OpenDJ, WebLogic, WebSphere, GitLab, source code, Zabbix, monitoring, vSphere, Veeam and Active Directory. Links to allegedly stolen archives are not reproduced.

Technical documentation

NVD / CISA — CVE-2021-35464

A critical deserialisation vulnerability in ForgeRock AM/OpenAM, exploitable without authentication for code execution. It is included in the Known Exploited Vulnerabilities catalogue.

nvd.nist.gov ↗
Technical documentation

GitLab — CVE-2021-22205

GitLab described the vulnerability as critical, with CVSS 10, allowing code execution through image processing. The fix was released on 14 April 2021, and GitLab confirmed exploitation of exposed self-managed instances.

about.gitlab.com ↗
Technical documentation

Microsoft — Windows Server 2012 R2 and SMBv1

Standard support for Windows Server 2012 R2 ended in 2023; ESUs can continue until October 2026. Microsoft says SMBv1 has significant security vulnerabilities and strongly recommends against its use.

Note

Status on 18 August 2026

e‑Terra is operating for authorised user groups, and about 100,000 requests were resolved between 11 and 17 August. The other platforms named by ANCPI remain unavailable. The institution says identified backups are being used for restoration and that there are no signs that electronic-document storage equipment was compromised. Final investigation findings and the precise impact on ePay users have not yet been published.

Final assessment

Extensive compromise and the extraction of some data are officially confirmed. Romania’s Government says the central cadastral database retained its integrity.

DNSC confirms extracted OpenDJ data, exposed source code, compromised passwords and the transfer of an Active Directory controller disk. On 18 August, e‑Terra is operating for authorised groups, and ANCPI reports about 100,000 requests resolved between 11 and 17 August. Other platforms remain unavailable. ANCPI says backups are being used for restoration and there are no signs that electronic-document storage was compromised, but the final report and precise impact on ePay users have not been published.