Ransomware attack on ANCPI: hackers accessed systems for 86 hours undetected

The largest cyber attack in ANCPI's history exploited outdated software and reused passwords. Hackers encrypted data with Black Basta and destroyed backup copies.

Ransomware attack on ANCPI: hackers accessed systems for 86 hours undetected

Black Basta ransomware paralysed the digital infrastructure of the Cadastre

The National Agency for Cadastre and Real Estate Publicity (ANCPI) has fallen victim to the largest cyber attack in its history, according to Cotidianul.ro. A technical report from the National Directorate of Cyber Security (DNSC) confirms that attackers remained undetected in the institution's networks for over 86 hours.

Initial access to ANCPI's infrastructure occurred on 10 July 2026, at 15:23 — a time established on the basis of screenshots later published by the attacker. The institution identified the incident only in the morning of 14 July, at 05:45. Thus, more than three and a half days passed before the attack was detected.

Known vulnerabilities, systematically exploited

DNSC found that the attack was not based on particularly sophisticated techniques. Among the problems identified were the use of old and unpatched software versions, lack of proper network segmentation, and the use of the same administrator passwords across multiple systems.

An additional deficiency was the absence of a centralised system for collecting and storing computer logs. Because of this, investigators were unable to confirm from internal sources the exact time of initial access. Some targeted virtual machines were subsequently deleted by attackers, complicating the investigation.

Encryption and destruction of backup copies

After entering the network, hackers moved laterally between several systems. The attack culminated in infrastructure encryption through the Black Basta ransomware. According to the DNSC report, attackers also destroyed backup copies of data before the final stage.

Among the services that became unavailable were the e-Terra application and the institution's email systems. ANCPI initially announced a "technical incident under investigation", later confirming that it was a cyber attack that affected all information systems.

The attacker publicly claimed responsibility

In the days that followed, a person with the pseudonym "ByteToBreach" claimed responsibility for the attack. Interviews with the suspected attacker appeared on multiple platforms and websites specialising in cyber security.

DNSC warned of the risk that excessive media coverage of attackers could turn them into public figures, calling for responsible reporting of such incidents and emphasising that attention should be directed towards prevention and combat.

ANCPI: the report is an interim analysis

ANCPI clarified that information recently appearing in the public domain does not represent completely new elements. The institution stressed that the technical document dated 22 July 2026 is an interim analysis by DNSC, intended for the competent authorities of the state.

The case brings back into discussion the state of information security in Romanian public administration. The DNSC report shows that an attacker can cause major damage by exploiting basic problems — unpatched software, reused passwords and absence of centralised monitoring — without needing particularly sophisticated tools.

Source: Cotidianul.ro

Read this article in the original language