The National Cyberint Center (CNC) sent 1,304 notifications to public institutions between 2021 and 2026 regarding technical, procedural, and human vulnerabilities, the head of the institution, Anton Rog, stated in Parliament. The disclosure was made during hearings on the ransomware attack that affected ANCPI on July 14, 2026, and blocked the e-Terra platform and real estate transactions for nearly a month.
According to the CNC, critical vulnerabilities at ANCPI were identified and reported as early as 2021 to the institution’s leadership, the Ministry of Development, and the prime minister at the time. However, according to Rog, the SRI did not receive an official response from the agency.
The attack was attributed to the ByteToBreach group, which allegedly deleted approximately 1,000 virtual servers. The DNSC identified weak and reused passwords, outdated systems, and permissive access rules. The institution stated that there are no indications that the databases were affected and that ANCPI’s activity could resume fully the following week.
The DNSC sent notifications to 2,400 institutions, flagging more than 40,000 vulnerabilities.
Parliamentarians warned that dozens or even hundreds of public institutions could face similar situations.
Sources
Latest News
08:13
07:49
07:46
07:33
07:23
See more news