A country stopped registering property on a Tuesday
On the night of 13 July the systems of Romania's National Agency for Cadastre and Real Estate Advertising stopped answering, and by Tuesday 14 July the e-Terra cadastral platform, the agency's websites and its email servers were all unreachable. ANCPI later described the event as the most serious technical incident in the institution's history. Romania's National Directorate for Cyber Security, DNSC, confirmed it as a cyberattack and characterised it as financially motivated, carried out with leaked credentials and known vulnerabilities rather than by a state actor. A week later the platform was still not back.
The practical effect was immediate and national. Notaries could not authenticate sales, register transfers or record mortgages, because in Romania those acts run through the register the attacker took offline. A threat actor using the handle ByteToBreach claimed responsibility, and by 15 July material said to come from the agency, including internal databases and source code, was being advertised for sale on a forum. The security firm KELA attributed the handle to Zakaria Mahdjoub, an alleged cybercriminal based in Oran, Algeria.
Two accounts of the same week
ANCPI's own notice is careful and narrow. It states that the technical and legal databases of the institution were not affected, and it warns readers that information circulating in public about the supposed consequences of the attack does not come from official sources. That is the agency's position, published on its own site, and it has not been withdrawn.
Security researchers and the attacker tell a harder version: entry with valid credentials, reconnaissance across internal systems, then destruction of systems and backups after an extortion attempt failed, with recovery resting on a copy held offline. Both accounts can be partly right, because a register can lose its production environment and still hold its legal record intact. For anyone outside the agency the distinction changes nothing that matters this month. Availability, not integrity, is what stopped the transactions.
Restoration is conditional. The tax date is not.
Read the agency's restoration plan closely and there is no date in it. ANCPI says applications are being migrated to the government cloud with completion estimated for Wednesday 22 July, after which authorised institutions will verify the systems and produce a report, after which service returns in phases according to operational priority. Affected systems stay isolated until every identified weakness has been addressed. That is a sequence of conditions, not a commitment, and it is the correct way to run a recovery. It is also unbounded.
Facing that unbounded sequence is a bounded one. Pre-sale agreements signed under Romania's reduced 9 percent VAT regime for new homes expire at the end of July, and the standard 21 percent rate then applies to eligible transactions. No extension has been announced. Twelve percentage points of a purchase price now depend on a clerical act that nobody in the country is able to perform. The same state controls both the outage and the deadline, and so far it has moved only one of them, which is neither.
There is no failover for a monopoly register
Owners buy redundancy for the parts of the stack they control. They keep a second cloud region, a second connectivity provider, a second payment processor. The single points of failure that actually stop a deal usually sit outside that perimeter: a land registry, a companies register, a VAT number checker, a national e-invoicing endpoint, an identity scheme. None of these can be dual-sourced, because the state is the only supplier, and the resilience you are relying on is entirely someone else's. In the United Kingdom the same dependency runs through HM Land Registry, and a British buyer has no more of a substitute than a Romanian one.
This is also not a freak event. Land registries in Poland, Slovakia, Greece, Morocco, Russia and Ukraine have been attacked within the past three years, which makes public register downtime a scheduled risk rather than an act of God. Under NIS2 the operators of these registers sit squarely in scope as public administration entities, but the directive obliges them to manage the risk, not to indemnify you for the week they are gone.
What to write down before your own week arrives
Take an hour and list every public register a transaction of yours cannot close without. For each one, record the legal fallback that exists when it is unavailable, whether that is a paper filing, a notarial deposit, a provisional entry or nothing at all, and name the person authorised to invoke it. Then ask counsel the question Romanian buyers are asking now: does a statutory deadline pause when the register needed to meet it is down? In Romania the answer is arriving after the deadline, which is the worst possible time to learn it.
On your own side of the line the lesson is narrower and older. The route in was leaked credentials plus vulnerabilities that were already known, which is the combination that has not required a single novel technique in years. Enforce phishing-resistant multi-factor authentication on every administrative account, expire credentials that appear in breach corpora without waiting for evidence of use, and keep at least one restore path that lives outside the credential set running production. The offline copy is the one an attacker holding your passwords cannot reach.
Read next: The nginx Patch Is Out, the Exploit Lands in August | ServiceNow Patched Its Cloud First, You 103 Days Later



