Raport DNSC | Cum a fost îngenuncheată infrastructura de la Cadastru de o breșă de securitate veche de 5 ani și de propriile vulnerabilități / Cine sunt atacatorii

The DNSC report on the cyberattack at ANCPI reveals that outdated software was exploited, leading to a significant data breach. Attackers infiltrated the network, destroyed backup data, and used ransomware to encrypt systems. Initial access was gained through a vulnerable identity management platform, allowing attackers to collect credentials and compromise internal servers. They executed a double extortion scheme, demanding ransom for decryption while threatening to publish stolen data. The attack's destructive phase involved systematically deleting recovery options, ultimately crippling ANCPI's operations. The group ByteToBreach claimed responsibility, showcasing their activities on cybercrime forums.