Three days without a country's land registry
Start with what citizens experienced, because it is the part every country should imagine happening to its own. According to public reporting, the national cadastre agency's core platform — the system every property transaction in the country depends on — stopped working, along with the institution's email. For roughly three days, notaries could not authenticate deeds, lawyers could not close transactions, surveyors could not file, and ordinary people could not buy, sell or register a home. An entire nation's property system simply stopped.
The first official explanation was technical problems. Only later did it become a confirmed cyberattack. That gap — between something is wrong and we are under attack — is itself a symptom, and it points straight at the root cause: when no one is monitoring for an intrusion, the first sign of a breach is not an alert. It is the service dying in public.
It was not just downtime — the crown jewels walked out
Ransomware that only encrypts is survivable if you have good backups. This was worse on every axis. According to the reporting, the attacker did not merely lock systems — they took the substance of the institution out the door: citizens' personal data from multiple databases, and a copy of a code repository holding the source code of the national systems themselves. Not only the data a registry keeps, but the blueprints of how it runs.
Then the two things that turn an incident into a catastrophe. The attacker was reported to be deleting the available backups — removing the very thing an organization relies on to recover — and the stolen data was put up for sale on underground forums. This is the modern shape of the threat: encrypt to stop you, exfiltrate to own you, destroy the backups so you cannot recover, and sell what was taken so the damage never ends. Against that, a nightly backup and a perimeter firewall are not a defense. They are a receipt.
The one sentence that explains the whole disaster
Here is the detail that turns this from a technical story into a lesson for every organization on earth. There was a contract. There were, on paper, obligations — around-the-clock support access, periodic audits, a two-hour response target for critical incidents. On paper, it looked covered.
But when the attack came, one supplier's reported defense captured the entire problem in a single image: it had provided the licenses, not the monitoring — it gave them the door; the attackers came in through the window. And, reportedly, the arrangement made no provision for a proper backup system at all. Read that again, because it is the failure in one line: buying security products is not the same as being defended. A license is a lock. It is not a guard. Nobody's job was to watch the house — so no one saw the window open, the data leave, or the backups vanish, until the whole country noticed at once.
What a SOC would have changed — at every single step
Walk the attack again, and place a Security Operations Center — someone watching the traffic and the logs around the clock, with the authority to act — beside each step. The difference is not marginal; it is the difference between an incident and a national headline.
- The intrusion. Attackers do not breach and drain a national database in an instant; they move for days. A SOC monitoring the environment sees the anomalies — the unusual access, the reconnaissance — long before anything is stolen.
- The exfiltration. An entire code repository and multiple databases being copied out is one of the loudest events on a network. Someone watching sees a mass data egress that should never happen, and moves on it.
- The backup deletion. This is where inline, autonomous response earns its name: backups being wiped in real time is exactly the moment a system must block, not merely record — cutting the attacker off mid-action instead of finding the empty backups later.
- The recovery. Offline, immutable backups — a basic resilience discipline any security operation insists on — mean deletion is a setback, not the end of the institution.
None of this is exotic technology. It is the ordinary work of security operations: watch continuously, detect early, block in real time, and stay ready to recover. It is precisely the layer that was missing.
This was not a fluke — and it is now the law
The most uncomfortable fact is that this was not a one-off. Months earlier, according to reporting, a national water authority in the same country was hit in a near-identical way. When two pieces of national critical infrastructure fall to the same kind of attack, the lesson is not bad luck. It is that owning tools without operating them is a systemic condition — and attackers know exactly where to find it.
This is also why regulation is catching up. Under the EU's NIS2 directive — and its equivalents worldwide — essential entities like a land registry are required not merely to buy security, but to manage and monitor it: to detect, to respond, and to demonstrate they can. Continuous monitoring is no longer a nice-to-have; for critical infrastructure it is a legal duty. The organizations that treat security as a product they purchased, rather than an operation they run, are the ones writing the next case study.
The lesson of this one is blunt, and it is universal: a lock is not a guard. Someone has to be watching, around the clock, and able to act the moment it matters. That is what a SOC is — and it is exactly what CYBER3.AI was built to be: an autonomous Security Operations Center that watches every device, detects early, and blocks in real time, so that the first sign of an attack is never your country reading about it.