www.euronews.ro Hacker Claims Responsibility for ANCPI Attack, Assures Data Not for Sale
Article Content
- •Hacker 'ByteToBreach' claims responsibility for ANCPI server breach.
- •Data from the breach is not intended for sale, according to the hacker.
- •ANCPI services remain offline, impacting land registration processes.
A hacker known as 'ByteToBreach' claims to have breached the servers of the Romanian National Agency for Cadastre and Land Registration (ANCPI). In an exclusive interview, he expressed remorse for the disruption caused to Romanian IT professionals and stated he would not sell the compromised data 'just to anyone.' The attack, which has rendered ANCPI services unavailable, reportedly exploited a known vulnerability from 2021. Rumors of a €10 million ransom were denied by the hacker, who emphasized that discussions of such nature are only for relevant parties. The ANCPI's digital services remain offline, affecting the processing of land registration requests. Authorities have confirmed that the hacker is not a state actor but a financially motivated individual. Investigations and remediation efforts are ongoing.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ByteToBreach in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…