Tuesday, 21 July 2026 · World
USD/EUR 0.8758 USD/GBP 0.7444 USD/JPY 162.5 USD/CNY 6.778 All rates →
RSS
EUROS The World Financial Report
Nº 10 Tuesday, 21 July 2026 · World Edition
LATEST
Europe

Cyberattack freezes Romanian property deals before VAT deadline

EUROS Newsroom · 4h ago · 2 min read
Cyberattack freezes Romanian property deals before VAT deadline

A cyberattack on Romania's digital land registry has frozen all property transactions, trapping buyers unable to finalize purchases before a costly VAT increase takes effect at the end of July.

A cyberattack has knocked Romania’s National Agency for Cadastre and Land Registration (ANCPI) offline since July 14, completely halting the nation's property market.

The outage hits at a critical juncture for the real estate sector. Buyers are currently unable to register new transactions, process pending applications, or obtain the land registry extracts required to close sales and secure mortgages. Because Romania relies entirely on a digital registry, there is no manual workaround to clear the backlog or bypass the system.

The freeze threatens to impose severe financial penalties on purchasers. Transactions tied to pre-sale agreements must be completed before July 31 to qualify for a temporary 9% value-added tax rate. After that date, the standard 21% rate applies to eligible transactions. This 12-percentage-point jump has created a surge in demand for closings that the crippled IT infrastructure simply cannot process.

Authorities are attempting to restore operations by migrating systems to the Government Cloud, a process expected to conclude on July 22. Once that migration is finished, authorized institutions must verify the integrity of application data and draw up a status report. Only after that review will ANCPI be able to provide a timeline for restoring services, as the agency stated it is prioritizing the isolation of affected systems and the remediation of vulnerabilities before going back online.

A hacker using the alias ByteToBreach has claimed responsibility for the breach, posting alleged screenshots of unauthorized access on a cybercrime forum. Israeli cybersecurity firm KELA identified the actor as a financially motivated criminal known for trading data stolen from airlines, banks and government institutions.

While ANCPI insists no confidential data was compromised, external researchers claim the attacker deleted the land registry database following a failed extortion attempt. The agency reportedly recovered the data from offline backups stored at multiple locations. Dan Cîmpean, head of Romania's National Cyber Security Directorate, told G4Media the attack was not complex and could have been prevented. He noted it exploited known vulnerabilities authorities had recently warned organisations to patch, alongside previously leaked credentials. Investigators have found no evidence that personal data or land certificates were stolen, though the attackers did exfiltrate user credentials and application source code.