Romania’s Land Registry Knocked Offline by Cyberattack Exploiting Unpatched Vulnerabilities and Leaked Credentials
What Happened — A coordinated cyberattack disabled the National Agency for Cadastre and Land Registration’s (ANC PCI) digital platforms, halting online land‑registry services for nearly a week. The attackers leveraged publicly disclosed software vulnerabilities that had not been patched and used previously leaked user credentials to gain initial access. investigators confirmed exfiltration of limited data, including user credentials and the e‑Terra application source code, but no personal property‑owner records were stolen.
Why It Matters for Compliance & Audit Readiness
- Unpatched software and credential reuse directly violate SOC 2 Access Control criteria (CC6.1‑CC6.4), underscoring the need for documented patch‑management and credential‑lifecycle processes.
- The incident demonstrates the value of continuous control monitoring and immutable audit evidence to prove that vulnerabilities are remediated promptly.
- Restoring services required a verified integrity check, a step that aligns with SOC 2’s requirement for evidence‑based change‑and‑configuration management.
Who Is Affected — Government agencies, real‑estate firms, notaries, lawyers, and other stakeholders that rely on Romania’s cadastral and land‑registry data.
Recommended Actions
- Map the breach to SOC 2 Access Control requirements and close gaps in patch‑management and credential‑rotation policies.
- Deploy automated vulnerability scanning and privileged‑access monitoring to generate continuous audit evidence.
- Conduct a post‑incident integrity verification of restored systems and retain logs as part of your SOC 2 evidence repository.
- Reinforce security‑awareness training for privileged users to mitigate credential‑theft risk.
Source: The Record – Romania cyberattack land registry
Technical Notes — Attack vector combined exploitation of known software vulnerabilities (unpatched components) and stolen credentials (initial‑access broker). Exfiltrated data comprised user credentials and e‑Terra source code; no personal cadastral records were confirmed stolen.