Comments

Hacker News

Poor password practice and policy, and likely a lack of 2FA / physical token security, seem to have contributed to this breach.

Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:

<https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...>

<https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...>

Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>.

NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.

by dredmorbius

The backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.

by osinix

Well, the land registry database in Serbia hasn't been working for two months now; the government hasn't issued any announcement so far, except for generic system-issue information we get from LRD support. Weird, hopefully we weren't hit too

by puritanicdev

Tangentially reminds me of what happened to the South Korean gov data center [1] where a no-backup ~900TB data center got erased due to a battery fire.

Withno external backups piecing together all the lost functions must havebeen hair raising, and more forensic archeolgy than data recovery.

Last i heard i think they had restored a quarter of the lost services/data.

[1] https://www.intermediagroup.org/south-korea-data-loss/

by rzerowan

    Security firm KELA... has doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria.

If I was an evil hacker, I would only hack countries my country hated or did not have extradition agreements with. Like the Russian hackers do.

Algeria has a extradition treaty with Romania:

https://periodicos.processus.com.br/index.php/egjf/article/v...

by khurs

Romanian friends have told me that this is really due to corruption.

Specifically:

- government gives IT/data contracts to cronies

- cronies don't actually do any real security work to protect the data

- things like this happen

by alexpotato

An update from the land registry (the truthfulness of this remains to be seen depending on how fast this comes back online):

ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.

After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.

ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.

According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.

The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.

The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.

by cbg0

> Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.

So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.

by skinfaxi

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Poor password practice and policy, and likely a lack of 2FA / physical token security, seem to have contributed to this breach.

    Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:

    <https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...>

    <https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...>

    Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>.

    NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.

  • The backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.
  • Well, the land registry database in Serbia hasn't been working for two months now; the government hasn't issued any announcement so far, except for generic system-issue information we get from LRD support. Weird, hopefully we weren't hit too
  • Tangentially reminds me of what happened to the South Korean gov data center [1] where a no-backup ~900TB data center got erased due to a battery fire.

    Withno external backups piecing together all the lost functions must havebeen hair raising, and more forensic archeolgy than data recovery.

    Last i heard i think they had restored a quarter of the lost services/data.

    [1] https://www.intermediagroup.org/south-korea-data-loss/

  •     Security firm KELA... has doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria.
    
    
    If I was an evil hacker, I would only hack countries my country hated or did not have extradition agreements with. Like the Russian hackers do.

    Algeria has a extradition treaty with Romania:

    https://periodicos.processus.com.br/index.php/egjf/article/v...

  • Romanian friends have told me that this is really due to corruption.

    Specifically:

    - government gives IT/data contracts to cronies

    - cronies don't actually do any real security work to protect the data

    - things like this happen

  • An update from the land registry (the truthfulness of this remains to be seen depending on how fast this comes back online):

    ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.

    After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.

    ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.

    According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.

    The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.

    The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.

    by cbg0
  • > Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.

    So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.