HomeBlog › Threat Lab
Case study

When Nobody Is Watching: How a Nation Lost Its Land Registry in Three Days

Updated 2026-07-18 · 8 min read · by Mihai Bătrîneanu
When Nobody Is Watching: How a Nation Lost Its Land Registry in Three Days

In three days, an entire EU member state lost the ability to buy, sell or register property — because the national agency that runs its land registry had bought security software and equipment, but had no one watching. In July 2026, Romania's National Agency for Cadastre and Real Property Publicity (ANCPI) was hit by a cyberattack that, according to public investigative reporting, took its core systems offline for days, exfiltrated citizens' data and the full source code of its national platforms, saw its backups deleted, and ended with the stolen data offered for sale online. It is a devastating case — and a clarifying one, because the failure was not exotic. It was the absence of the one thing that turns security products into security: operations. Someone watching, and able to act, in real time. This is what the lack of a SOC actually costs — told through a public case any country could repeat.

ContentsThree days without a country's land registry
It was not just downtime — the crown jewels walked out
The one sentence that explains the whole disaster
What a SOC would have changed — at every single step
This was not a fluke — and it is now the law
Frequently asked questions

Three days without a country's land registry

Start with what citizens experienced, because it is the part every country should imagine happening to its own. According to public reporting, the national cadastre agency's core platform — the system every property transaction in the country depends on — stopped working, along with the institution's email. For roughly three days, notaries could not authenticate deeds, lawyers could not close transactions, surveyors could not file, and ordinary people could not buy, sell or register a home. An entire nation's property system simply stopped.

The first official explanation was technical problems. Only later did it become a confirmed cyberattack. That gap — between something is wrong and we are under attack — is itself a symptom, and it points straight at the root cause: when no one is monitoring for an intrusion, the first sign of a breach is not an alert. It is the service dying in public.

It was not just downtime — the crown jewels walked out

Ransomware that only encrypts is survivable if you have good backups. This was worse on every axis. According to the reporting, the attacker did not merely lock systems — they took the substance of the institution out the door: citizens' personal data from multiple databases, and a copy of a code repository holding the source code of the national systems themselves. Not only the data a registry keeps, but the blueprints of how it runs.

Then the two things that turn an incident into a catastrophe. The attacker was reported to be deleting the available backups — removing the very thing an organization relies on to recover — and the stolen data was put up for sale on underground forums. This is the modern shape of the threat: encrypt to stop you, exfiltrate to own you, destroy the backups so you cannot recover, and sell what was taken so the damage never ends. Against that, a nightly backup and a perimeter firewall are not a defense. They are a receipt.

The one sentence that explains the whole disaster

Here is the detail that turns this from a technical story into a lesson for every organization on earth. There was a contract. There were, on paper, obligations — around-the-clock support access, periodic audits, a two-hour response target for critical incidents. On paper, it looked covered.

But when the attack came, one supplier's reported defense captured the entire problem in a single image: it had provided the licenses, not the monitoring — it gave them the door; the attackers came in through the window. And, reportedly, the arrangement made no provision for a proper backup system at all. Read that again, because it is the failure in one line: buying security products is not the same as being defended. A license is a lock. It is not a guard. Nobody's job was to watch the house — so no one saw the window open, the data leave, or the backups vanish, until the whole country noticed at once.

What a SOC would have changed — at every single step

Walk the attack again, and place a Security Operations Center — someone watching the traffic and the logs around the clock, with the authority to act — beside each step. The difference is not marginal; it is the difference between an incident and a national headline.

None of this is exotic technology. It is the ordinary work of security operations: watch continuously, detect early, block in real time, and stay ready to recover. It is precisely the layer that was missing.

This was not a fluke — and it is now the law

The most uncomfortable fact is that this was not a one-off. Months earlier, according to reporting, a national water authority in the same country was hit in a near-identical way. When two pieces of national critical infrastructure fall to the same kind of attack, the lesson is not bad luck. It is that owning tools without operating them is a systemic condition — and attackers know exactly where to find it.

This is also why regulation is catching up. Under the EU's NIS2 directive — and its equivalents worldwide — essential entities like a land registry are required not merely to buy security, but to manage and monitor it: to detect, to respond, and to demonstrate they can. Continuous monitoring is no longer a nice-to-have; for critical infrastructure it is a legal duty. The organizations that treat security as a product they purchased, rather than an operation they run, are the ones writing the next case study.

The lesson of this one is blunt, and it is universal: a lock is not a guard. Someone has to be watching, around the clock, and able to act the moment it matters. That is what a SOC is — and it is exactly what CYBER3.AI was built to be: an autonomous Security Operations Center that watches every device, detects early, and blocks in real time, so that the first sign of an attack is never your country reading about it.

A lock is not a guard. Someone has to be watching.
CYBER3.AI is an autonomous Cloud SOC — it monitors your environment around the clock, detects intrusions early, and blocks attacks inline in real time, across every device including the OT and legacy systems that run critical infrastructure. Detection and response, operated for you — not just licensed to you.
Explore CYBER3.AI Cloud SOC →
🛡️ Try CYBER3.AI free
AI security copilot + Global Scan of your own network. 700 free credits on sign-up — no card, no strings.
Start free →
About the author: Mihai Bătrîneanu
Founder of CYBER3.AI and a 30-year veteran of internet infrastructure. In 1994 he founded PC-NET, the first Internet Service Provider in Eastern Europe, and built Romania's first e-mail, ADSL broadband and VoIP services. He now builds CYBER3.AI — a sovereign Security LLM and autonomous Security Operations Center.

Frequently asked questions

What happened in the 2026 ANCPI (Romania cadastre) cyberattack?

According to public investigative reporting, in July 2026 Romania's National Agency for Cadastre and Real Property Publicity (ANCPI) was hit by a cyberattack that took its core e-Terra platform and email offline for roughly three days, halting property transactions nationwide for citizens, notaries and lawyers. The attacker reportedly exfiltrated citizens' data and a copy of the source code of the national systems, deleted available backups, and put the stolen data up for sale online. It is examined here as a case study in the cost of lacking security operations.

Could a SOC have prevented the land registry attack?

A Security Operations Center cannot guarantee that no breach ever occurs, but it changes the outcome at every stage. Continuous monitoring detects an intrusion and reconnaissance days before data is stolen; it flags a mass exfiltration of databases and source code as it happens; and inline, autonomous response can block backup deletion in real time rather than discovering the empty backups afterward. The reported failure in this case was precisely that no one was monitoring — the exact gap a SOC exists to close.

Why isn't buying security software or equipment enough?

Because products are tools, not operations. A firewall, a license or an appliance is a lock; it does not watch the environment, correlate signals, or act when an attacker is already inside. Real defense requires someone — or an autonomous system — continuously monitoring, detecting early and responding in real time. In this case, obligations existed on paper, but a supplier's reported position was that it provided licenses, not attack detection: the door, not the guard. Owning security is not the same as operating it.

What is the difference between a security vendor and a SOC?

A security vendor typically supplies products — software, licenses, equipment — and may offer support. A Security Operations Center operates security: it watches the environment around the clock, hunts for and detects intrusions, investigates them, and responds, ideally blocking attacks in real time. The distinction is captured by a defense reported in this case — the supplier provided the door; the attackers came through the window. Someone has to be operating the guard, not just selling the lock.

How does NIS2 apply to critical infrastructure like a land registry?

The EU NIS2 directive designates essential and important entities — including public administration and critical services — and requires them to manage cybersecurity risk actively: to implement detection and response, monitor continuously, handle incidents, and demonstrate that they do. It is not satisfied by owning security tools. An organization running national infrastructure such as a land registry is expected to operate security, not merely purchase it, and to prove it — exactly the capability whose absence this case exposes.

Protejează-ți telefonul — CYBER3, gratuit pe Google Play
Instalează