The press release issued by the Government yesterday about the cyberattack that paralyzed the National Agency for Cadastre and Real Estate Advertising two weeks ago tries to transform a major institutional failure into a reassuring story about "reconstruction”, "careful coordination” and "necessary lessons”. However, the interim technical report of the National Directorate of Cyber Security shows a radically different reality: the attackers exploited critical vulnerabilities known for years, penetrated an infrastructure protected by equipment and applications that were out of support, found an almost unsegmented network, obtained administrative credentials reused on several systems, reached most of the physical and virtual equipment, copied source code, user data and at least one critical virtual machine, then deleted approximately 100 virtual machines and backup files.
However, the Executive, in the cited press release, systematically avoids the very information that allows for establishing responsibility: how the attack was possible, what elementary measures were missing, how much data was compromised, who was supposed to ensure security and who will be responsible for the fact that the real estate market in our country was blocked for more than ten days.
The first cosmeticization of the situation appears right in the chronology. The Government release states that "on July 14, 2026, ANCPI found unauthorized access", while the DNSC analysis records in the cited technical report that ANCPI notified the Directorate on July 14 in connection with "a cyber incident detected on July 13, 2026". In fact, more precisely, according to DNSC, the attacker had entered the system as early as July 10, at 15:23:57, and the incident was actually detected by ANCPI staff only on July 14, at 05:45. DNSC calculates a time frame of over 86 hours between initial access and detection. For three and a half days, the attacker was able to move through the infrastructure, scan the network, collect credentials, copy data, and prepare to destroy systems without any ANCPI employee noticing. This is not a simple calendar ambiguity, but one of the main dimensions of the security failure, conveniently omitted from the Government statement.
Even the phrase that the attackers "encrypted and deleted part of the virtualization infrastructure” does not convey the scale of the disaster. DNSC determined that the ByteToBreach group carried out a double extortion ransomware attack, meaning that it did not limit itself to blocking systems, but also sought to copy data in order to blackmail the victim into publishing or selling it. The attacker had access to most of the infrastructure devices, virtual and physical, to network equipment, to Active Directory Domain Controller servers, and to source code repositories. An order identified by DNSC confirms the external transfer of the virtual machine "DC1”, an Active Directory domain controller - one of the most sensitive components of a network, as it contains information about identities, accounts and access rights. The report explicitly mentions the exfiltration of some virtual machines, the deletion of backups, the encryption of files and the publication of fragments of the stolen data on dark web forums. The reduction of this extensive compromise to "part of the virtualization infrastructure” is an administrative formulation intended to hide the technical seriousness of the incident.
The most problematic part of the press release issued by the Executive yesterday, however, is that relating to the data. The Government states that the central cadastral database was not affected, that there is no evidence of its access and that the integrity of the cadastral and land registry records is confirmed. The statement may be correct strictly regarding the Oracle Exadata database containing the property records, because DNSC says that the available evidence does not demonstrate its access. But the press release uses this limited finding to create the general impression that citizens' data was not compromised. However, the DNSC's interim technical report establishes the opposite regarding ePay users: the attacker gained access to the OpenDJ/LDAP user database and extracted an estimated volume of approximately two million records, containing names, email addresses, identifiers and password hashes. DNSC shows that the information appears to belong to external users of the platform, identified including by personal Gmail and Yahoo addresses. Therefore, we are no longer just talking about a suspicion that will "be established" sometime by the investigation, but about a compromise described in the interim technical report of the competent national authority.
The recommendation in the aforementioned press release regarding the fact that ePay users should change their password, "especially if they use it on other accounts", becomes an indirect recognition of the data compromise, without explicit disclosure. The government asks people to protect themselves, but avoids telling them exactly why. It also does not specify whether the passwords were stored using modern algorithms and with individual hops, whether all active sessions and authentication tokens were invalidated, whether the affected users will be informed individually, and whether the incident was notified to the National Authority for the Supervision of Personal Data Processing within the time limit provided for by the GDPR. It also does not say whether all administrative credentials and potentially compromised certificates were revoked and replaced. This is essential information for the security of citizens, not details that can be hidden behind the "confidentiality of the investigation”.
The government statement also completely omits the probable technical cause of the attack. DNSC says the initial point of entry was the OpenAM/ForgeRock authentication platform in the path to ePay, which was exposed on the internet and vulnerable to known security issues, and that the attacker exploited public vulnerabilities, one of which was known as early as 2021. Once inside, he found an unauthenticated Java JMX/RMI management interface, obtained code execution, decrypted administrative credentials, and used the ePay server as a pivot point to the central virtualization infrastructure.
More seriously, the DNSC report describes what it calls a combination of "structural weaknesses” in ANCPI's security, as firewalls were running outdated versions, some of which were out of official support and lacking security updates, and the Bitdefender antivirus malware only worked on employee devices, not on the critical servers analyzed. Furthermore, the internal network was "almost” unsegmented, so a compromised production server could communicate directly with the vCenter management infrastructure. The same administrative credentials were reused on multiple devices and services, so obtaining a single password gave the attacker access to critical components.
This is the fundamental information that the Government's press release hides. Even moving ANCPI applications to the government cloud cannot be presented by the Government as a saving solution. The cloud may provide a better managed infrastructure, but it does not fix vulnerable code, faulty architecture, compromised credentials or negligent administrative practices. If the "current version” of the system is restarted before all vulnerabilities are fixed, the problem is simply moved to a new data center. The director of ANCPI, Laurenţiu Blaga, himself had stated that the applications, not the database, would be moved to the cloud, and that verification of possible breaches would be done later. Now, the press release talks about restarting "on the current version”, followed by subsequent updates. This very rush needs to be explained: what vulnerabilities remain temporarily open, what compensating controls are implemented, and who takes responsibility for the decision to restart?
There is also the issue of contracts paid for with public money. The press documented two agreements for cyber protection services awarded to IT About IT SRL, one for almost 950,000 lei in 2019 and another for 1.48 million lei in 2023, as well as a maintenance contract for e-Terra for 15.77 million lei awarded to Wing Leading Edge SRL. The last subsequent security contract was allegedly signed on April 30, 2026, less than three months before the attack. The Government statement does not say who was contractually responsible for updating vulnerable components, who was supposed to verify network segmentation, who accepted equipment that was out of support, who configured log retention for only seven minutes, and what security audits were performed.













































Reader's Opinion