Informat.Ro Cyberattacks Target Romanian Public Institutions, Data Compromised
Article Content
- •ANCPI suffered a severe cyberattack, marking the worst incident in its history.
- •Phishing campaigns using cloned government portals are targeting citizens.
- •The hacker group 'ByteToBreach' has claimed responsibility and is selling stolen data.
A wave of cyberattacks has targeted several Romanian public institutions, primarily affecting the National Agency for Cadastre and Land Registration (ANCPI) and the Ministry of Investments and European Projects. The attacks began on July 14, 2026, leading to significant disruptions, including the e-Terra application becoming non-functional. A phishing campaign utilizing a cloned version of the government payment portal ghiseul.ro has also been reported. The hacker group 'ByteToBreach' claimed responsibility for the ANCPI breach, exploiting a known vulnerability from 2021 and allegedly selling stolen data online. The ANCPI described this incident as the most severe technical attack in its history, with ongoing investigations into potential ransom demands. Authorities have confirmed that personal data of Romanian citizens has been compromised, raising concerns about the security of sensitive information. The Romanian government has issued warnings to citizens regarding phishing attempts related to traffic fines.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (25)
Following this threat?
Track ByteToBreach and Agenția Pentru Cadastru in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI-Driven Cyber Threats Target Telecom and Financial Sectors Telecom networks are increasingly targeted by AI-assisted cybercriminals, with a reported 72% rise in AI-related attacks in 2025, causing an estimated $30 billion in damages. Key threats include the use of synthetic identities and deepfakes, particularly affecting mobile money platforms in emerging markets. Notable…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…