Was your data stolen from ANCPI? What is confirmed, what is not and what to do now
After the cyberattack on ANCPI, the natural question is “was my data stolen?”. In brief: no personal data theft has been officially confirmed, and ANCPI says land register data were not affected. The attacker nevertheless claims to have stolen data. We show you what is confirmed, what is merely a claim and what practical steps you can take.

- ANCPI confirmed a cyberattack; e-Terra and the other services were unavailable.
- The DNSC director publicly stated that no personal data theft had been detected.
- On 27 July, the government confirmed that it was a ransomware attack, but that the central cadastral database was not affected.
- The ByteToBreach group nevertheless claims to have stolen citizens' data and source code, but the claim is not officially confirmed.
- ANCPI says the technical and legal databases were not affected and entries remain valid.
- As a reasonable precaution, if you had an account on an ANCPI portal, change your password, especially if you reused it elsewhere.
- Officially confirmedOfficial ANCPI or DNSC statement, with a public source.
- Attacker's claim · unverifiedAn attacker's claim, unconfirmed by the authorities.
- Verifi precautionOur security hygiene recommendation, not a factual assertion.
- 14 July 2026 - the date ANCPI publicly announced that its IT systems were unavailable; on 15 July it confirmed the cause, a cyberattack (ancpi.ro)
- no personal data theft detected - the DNSC director's public position on the incident; the institution also says the attack could have been prevented (DNSC, press, July 2026)
- unconfirmed claim - the ByteToBreach group claims to have stolen citizens' data and source code; ANCPI and DNSC do not confirm this (public OSINT profiles)
- valid entries - according to ANCPI, the technical and legal databases were not affected, and land register entries remain valid (ancpi.ro)
- ransomware attack - the nature of the incident, officially confirmed by the government: attackers encrypted and deleted part of the virtualisation infrastructure; the central cadastral database was not affected (government statement, 27 July 2026)
- ePay password change - a precaution officially recommended to payment platform users following this type of incident (government statement, 27 July 2026)
What is officially confirmed
On 14 July 2026, ANCPI publicly announced that some of its IT systems were unavailable. On 15 July, the institution confirmed the cause: a cyberattack, described as the most extensive technical outage in its history.
The director of Directoratul Național de Securitate Cibernetică (DNSC) publicly stated that the attack could have been prevented and that, according to checks so far, no personal data theft had been detected.
ANCPI, in turn, stated that the technical and legal databases were not affected, that the data had not been compromised or stolen, and that land register entries remain valid.
On 27 July 2026, the government published a statement on progress in restoring e-Terra, officially confirming the nature of the incident: a ransomware attack in which the attackers encrypted and deleted part of the virtualisation infrastructure hosting the agency's applications. The statement says that the central database of the cadastral system was not affected and that there is no evidence that the attackers had access to these data.
The same statement recommends that users of the ePay payment platform change their password, as a precaution specific to this type of incident.
What the attacker claims (unverified)
Responsibility for the attack was claimed by a group publicly known as ByteToBreach, described in security analyses as a financially motivated actor that compromises internet-exposed systems and attempts to monetise the data.
The attacker claims to have obtained citizens' data and a copy of the source code of some ANCPI applications, and to have offered them for sale on forums. These are its own claims, made partly to promote its “goods”.
Is my data at risk?
To answer properly, separate two different things that are easily confused:
- Land register data (owner, encumbrances, areas). They are managed by ANCPI, which says they were not affected and the entries remain valid.
- Your account on ANCPI portals. If you have ever paid online for a document (for example, through the payment platform), you have an account with an email address and password. This is the layer worth treating cautiously.
For the land register, the official position is that it was not affected; request an updated extract before a transaction anyway, as always. For your account, even without officially confirmed theft, it is prudent to treat any account on a compromised system as potentially exposed. This is not panic; it is security hygiene.
What to do now: precautionary steps
- If you had an account on an ANCPI portal, change your password once the service returns. For the ePay payment platform, this is officially recommended in the government statement of 27 July.
- If you used the same password elsewhere, change it there too. Password reuse is the greatest actual risk, independently of this incident.
- Enable two-factor authentication (2FA) wherever available.
- Beware of phishing “from ANCPI”: messages or calls requesting data, passwords or payments. ANCPI does not ask for your password by email or telephone.
- Do not repeatedly re-enter card details if a portal appears not to be working.
What does NOT change
- Your ownership right recorded in the land register does not disappear because of a cyberattack.
- Valid documents remain valid; ANCPI has stated that entries remain valid.
- The incident does not itself change your legal position. Only an updated extract confirms it, after the service returns and before signing.
Have a transaction in progress?
The practical effect of the incident concerns services (for example, the land register extract needed by the notary), not your ownership right. For live service status, the timeline and practical steps for ongoing transactions, see the dedicated page:
ANCPI and e-Terra are not working: cyberattack, live status and what to do about your transaction.
Sources and methodology
We separate officially confirmed information from the attacker's claims and unverified reports. Verifi does not independently investigate the cyber incident; we update this page when new official statements appear.
- Guvernul României, progress on restoring e-TerraStatement, 27 July 2026
- ANCPI, official updates on the incidentThe institution's position
- ANCPI statement of 15 July on the cyberattackArchived by AGERPRES
- The DNSC director's statements on the incidentPress, July 2026
- ByteToBreach OSINT profile (SOCRadar)Public security analysis
- ByteToBreach analysis (KELA)Public security analysis
Frequently asked questions
Was my data stolen from ANCPI?
There is no official confirmation of personal data theft. ANCPI stated that the technical and legal databases were not affected, and the DNSC director publicly stated that no personal data theft had been detected. The ByteToBreach group nevertheless claims to have stolen data, but the authorities have not confirmed the claim. As a reasonable precaution, treat your account on ANCPI portals as potentially exposed.
Should I change my ANCPI password?
Yes, this is recommended. For users of the ePay payment platform, changing the password is officially recommended in the government statement of 27 July 2026 as a precaution following this type of incident. Change it once the service returns. In particular, if you used the same password elsewhere (email, bank, other accounts), change it there too: password reuse is the greatest actual risk, independently of this incident.
Who is ByteToBreach?
A publicly known cyber actor, described in security analyses such as SOCRadar and KELA as financially motivated, compromising internet-exposed systems and attempting to monetise the data obtained. It claimed responsibility for the attack on ANCPI. What it actually obtained remains, at this point, its own claim, unconfirmed by ANCPI or DNSC.
Is land register data at risk?
According to ANCPI, the technical and legal databases were not affected, and land register entries remain valid. This is the institution's official position, not an independent verification by Verifi. Before any transaction, request an updated land register extract once the service returns anyway.
Could my data be sold on the dark web?
The attacker claims to have offered data for sale, but there is no official confirmation of which data or whether they concern you. You cannot control what an attacker does, but you can reduce your risk: change reused passwords, enable two-factor authentication and watch for phishing messages invoking this incident.
What does this mean for an ongoing transaction?
The practical impact concerns ANCPI services (for example, the land register extract needed by the notary), not your ownership right. See the live service status and transaction steps on the ANCPI status page, and request an updated extract before signing.