Over 600,000 property records stolen from Register Centre – pre-trial investigation launched

Data misappropriated from the Register Centre includes more than 600,000 property register records. The logins were executed from abroad using credentials of Migration Department employees. Among those affected are the president, the commander of the armed forces, ministers, and members of parliamen

Over 600,000 property records stolen from Register Centre – pre-trial investigation launched

Hundreds of thousands of data stolen from Register Centre – Prosecutor General's office investigates large-scale cyber crime

The Prosecutor General's office is conducting an investigation into mass data theft from the Register Centre. Perpetrators unlawfully misappropriated over 600,000 records from the property register, among which were individuals' personal identification codes. Foreigners breached the system using the credentials of two Migration Department employees.

Interior Minister Vladislavas Kondratovičius LRT.lt recounted that the crime came to light when a private citizen asked in late February why the Migration Department was checking his property data. It turned out that an institutional employee had no idea that unknown persons were using his login credentials.

After receiving confirmation from the Register Centre that official employees had not accessed the data, and that the credentials were being used unlawfully, all Migration Department accounts in the Register Centre system were immediately frozen, all passwords were changed, and the incident was reported to the National Cyber Security Centre and the Data Protection Authority.

The data loss affected the country's highest-ranking officials: among those affected are President Gitanas Nausėda, armed forces commander Raimundas Vaikšnoras, some ministers, parliamentarians, and business representatives. The unlawful use of data began in early this year, with the breach detected in early April.

Interim Register Centre director Giedrius Cininas stated that suspicious logins were detected in early April, and by 10 April the scope of the stolen information had been established. Following this scandal, Register Centre director Adrijus Jusas stepped down from his post.

A representative of the State Data Protection Inspectorate, Danguolė Morkūnienė, explained that the General Data Protection Regulation permits postponement of notifying residents about data security breaches if urgent notification could hinder pre-trial investigation.

Source: LRT

Read this article in the original language