A cyberattack on Romania’s national land registry has disrupted property transactions across the country after taking critical digital services offline.
The incident affected systems operated by the National Agency for Cadastre and Land Registration, including e-Terra, the platform used to manage cadastral and land registration information.
Its failure prevented notaries from obtaining land registry extracts needed to authenticate property sales and register mortgages. New applications could not be submitted normally, while existing cases were left unprocessed.
The attack was reported to Romania’s National Cyber Security Directorate on 14 July. The agency’s email and other internal applications were also made unavailable as affected infrastructure was isolated and examined.
DATABASES UNAFFECTED
The land registry agency subsequently said its core technical and legal databases had not been affected. These contain cadastral information such as property boundaries and maps, alongside legal records covering ownership and mortgages.
It also said backup copies were stored in several locations, providing redundancy and allowing information to be restored following a cyber incident.
Claims that the country’s entire land registry database was deleted have circulated online but remain unverified. They appear to originate from the suspected attacker and unnamed sources rather than Romania’s authorities.
Romanian cybersecurity officials said investigators had identified limited data extraction involving credentials and parts of application source code but had not detected the theft of personal information or land registry certificates at that stage.
RESTORATION WORK
Applications were being migrated to Romania’s government cloud before undergoing security and data-integrity checks. Services were expected to return in stages once the responsible authorities were satisfied that vulnerabilities had been addressed.
The incident demonstrates how disruption to the digital infrastructure supporting property ownership can quickly affect estate agents, lenders, conveyancers, notaries and consumers – even where the underlying ownership records remain intact.
It also highlights the importance of cyber resilience, secure offline backups and workable continuity arrangements as property markets become increasingly dependent on interconnected digital data.
For the UK, the attack provides a timely case study as the Government and property industry pursue greater digitisation and Smart Data adoption throughout the homebuying process.
STRONG GOVERNANCE
Maria Harris (main picture, inset), chair of the OPDA, said: “The cyberattack on Romania’s Land Registry highlights the importance of strong governance, security standards and oversight in any digital data-sharing ecosystem.
“The Romanian Land Registry is a centralised system rather than a trust framework, and it does not publicly set out the technical and security standards it operates to beyond EU and GDPR requirements.
“By contrast, the Smart Property Data Scheme being developed in the UK is being designed around a framework of accreditation, accountability and ongoing assurance.
MINIMUM STANDARDS
And she added: “The Scheme will set, monitor and govern the performance of all participants against minimum standards covering cyber security, data protection and secure data-exchange protocols.
“Organisations will need to demonstrate compliance with these requirements to participate, helping to create a trusted and resilient ecosystem.
“While no digital environment can eliminate cyber risk entirely, robust standards, oversight and clear accountability will play a critical role in ensuring property data can be shared safely and securely, giving consumers and industry greater confidence in the homebuying process.”




