ROMANIA LAND REGISTRY DISRUPTED BY CYBER ATTACK
A cyberattack wiped Romania’s land registry database, disrupting real estate transactions nationwide after the hack destroyed production systems and backups following a failed extortion attempt. According to experts, the attack, which began July 14, points to a threat actor known as ByteToBreach. The attacker apparently gained access using valid credentials, allowing it to bypass perimeter defenses before conducting reconnaissance across the agency’s network. After mapping internal systems, the attacker deleted critical data and disabled key services, including the land registry database, official applications, websites and email servers. The outage prevented notaries, government officials and citizens from accessing essential property records, effectively bringing Romania’s real estate market to a standstill.
Reports said the attacker also stole sensitive information, including employee credentials, internal documents and network details, before offering the stolen data for sale on a hacking forum. The destructive actions followed an unsuccessful attempt to extort the agency. Romanian authorities have begun rebuilding the affected infrastructure using an offline backup.
Hackers have been intensifying supply-chain attacks by compromising open-source software hosted on repositories, including npm for JavaScript packages and PyPi for Python libraries, at least since early 2024, when a nation-state compromised data compression software XZ Utils. Amazon now says it believes with medium confidence that the same financially motivated Pyongyang actor commonly tracked as Sapphire Sleet or Stardust Chollima is behind the compromise of JavaScript packages Axios, Debug, Chalk and Typo-Crypto. Amazon makes the assessment of North Korean responsibility with high confidence. It’s only whether the same Pyongyang threat actor was involved in all four cases that needs independent verification, said CJ Moses, vice president of Amazon engineering.


