A hacker has completely deleted the land registry database in Romania, effectively shutting down the country's real estate market. The attacker gained access using valid credentials and systematically destroyed backups to prevent recovery efforts.
The breach exposed far more than just property records. Internal documents, employee credentials, and copies of GitLab servers containing source code were all compromised. The scope of the attack suggests a sophisticated operation designed not just to steal data, but to cause maximum operational disruption.
The use of legitimate credentials indicates either a compromised insider or credentials obtained through prior reconnaissance. By targeting backups alongside the primary database, the attacker clearly intended to leave the organization with minimal recovery options, turning the incident from a data theft into a business-crippling infrastructure attack.

