The stolen data following the cyberattack on the National Agency for Cadastre and Real Estate Advertising (ANCPI) has been put up for sale on a forum frequented by cybercriminals. The attacker claims to have obtained the source code of the institution’s main information systems and states that they have started deleting available backups.
According to an investigation by Public Record, the announcement was posted on July 15, shortly after the e-Terra application and other ANCPI information systems became unavailable following the cyberattack.
The message’s title is provocative: „[RO] Thy arss shall be spanked, Romania! [ANCPI]” (translated freely as „Romania, you’re going to get spanked!”).
In the description, the attacker claims to possess „data of Romanian citizens obtained from various databases collected through ANCPI networks,” as well as a copy of GitLab servers containing the source code of the institution’s systems, including the e-Terra and RENNS applications.
Additionally, they state that the institution presented the incident as a mere technical issue, although in their opinion, the situation is much more serious.
### Hacker Claims to Have Started Deleting Backups
In one of the screenshots published alongside the announcement, a message appears stating that the attacker has started deleting available system backups.
Backups are data backups used to restore systems after cyber incidents or other malfunctions.
The Israeli cybersecurity company Kela describes the attacker as a cybercriminal with technical skills who commercializes sensitive data obtained from airlines, banks, and government institutions from multiple countries, including the USA, Poland, Ukraine, Cyprus, Chile, Kazakhstan, and Uzbekistan.
### Million-Dollar Contracts for Cybersecurity
The Public Record investigation shows that ANCPI signed two framework contracts for cybersecurity services with the same company, IT About IT SRL, in 2019 and 2023, worth nearly 950,000 lei and almost 1.5 million lei, respectively.
According to the specifications of the latest tender, the security solution implemented at ANCPI was considered „of national importance,” and the provider was required to ensure continuous support, technical interventions, annual audits, and system updates based on Bitdefender technologies.
The documentation even sets response times of two hours for critical incidents and eight hours for major ones.
When contacted by Public Record reporters, IT About IT representative Ovidiu Raoul Berdilă stated that his company only supplies licenses and was not contractually obligated to detect cyberattacks.
However, the publication notes that the „malfunction” definition in the specifications explicitly includes situations caused by cyberattacks and viruses affecting system operation.
ANCPI has communicated that the incident is still under investigation in collaboration with several institutions and has not provided further details until the investigation is published.
### The Attack Has Blocked ANCPI Systems
The ANCPI’s computer applications have been unavailable for almost three days.
The institution initially announced technical issues but later confirmed that the systems were affected by a cyberattack.
As a result, the e-Terra application and the cadastre and land registry services cannot be used by citizens, notaries, lawyers, or land surveyors. Additionally, the institution’s email addresses have been unavailable.
Authorities previously stated that the computer platforms would remain non-functional at least until the end of the week while specialists work to remedy the attack’s effects.
