www.realitatea.net Ransomware Attack Targets Romania's National Penitentiary Administration
Article Content
- •ANP suffered a ransomware attack on July 29, 2026, impacting multiple systems.
- •Immediate isolation of affected equipment was implemented to limit further damage.
- •Backup systems may reduce the overall impact of the data compromise.
On July 29, 2026, Romania's National Penitentiary Administration (ANP) was hit by a ransomware attack affecting multiple workstations and servers. The attack prompted immediate isolation of affected equipment to limit damage, and several services were temporarily shut down. ANP's director, Geo-Bogdan Burcu, indicated that while the extent of data loss is still being assessed, existing backups may mitigate the impact. The IT team is collaborating with the National Cyber Security Directorate to investigate the incident and restore services. A formal complaint will be filed with DIICOT to further address the attack. The situation is currently under control, with the administration operating in a limited capacity to ensure the rights of incarcerated individuals are maintained.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Administrația Națională A Penitenciarelor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…