10 min read

The Hacker Didn’t Steal the Deed. He Deleted It.

The Hacker Didn't Steal the Deed. He Deleted It.

THE TECHNOLOGY BLIND SPOT

Ana Stan could not do her job. The Romanian notary said it plainly in a post that circulated the week her country’s property market stopped: since Tuesday she could not issue a land registry extract, could not authenticate a sale, could not register a mortgage. The Tuesday she meant was July 14, 2026, the morning notaries across Romania watched the national cadastre system return the same server error. The system did not come back that day. It did not come back that week.

The error message was the visible end of a crime that had been running quietly for some time. A hacker operating under the name ByteToBreach had logged into the systems of the National Agency for Cadastre and Real Estate Advertising, known as ANCPI, using valid credentials. No exploit. No malware at the door. Someone’s username and password worked, and the intruder spent the quiet period mapping the network. [See Nobody Hacked the Database, Somebody Logged In, The Technology Blind Spot (2026).] Then came an extortion demand. ANCPI refused to pay. So the hacker did the thing that separates this incident from nearly every breach the legal profession has trained itself to fear: he deleted the country’s land registry.

Not encrypted for ransom. Not leaked for spite. Deleted, along with internal documents and employee credentials, and, by the attacker’s own boast, the stolen copies he held, so that no one could restore the data from his side either. Sources told the security publication Risky Business that the wipe reached backup systems as well. Romania sells between 150,000 and 170,000 residential units a year, and for more than a week no notary could close a single one. Timing sharpened the pain. Romania’s VAT rate on new homes jumps from 9 percent to 21 percent on August 1, and buyers racing that deadline watched thousands of euros in tax exposure pile up while the registry sat dark.

One fact kept the story from becoming a catastrophe measured in decades. ANCPI maintained offline backup copies at several designated storage locations, and those copies survived. The agency called the event the most serious technical incident in its history, began rebuilding its network from scratch, and started migrating its applications to the Romanian government cloud. The register lived because a copy of it existed somewhere a stolen password could not reach.

The aftermath produced two statements worth reading side by side. ANCPI insisted that its core technical and legal databases were neither altered nor destroyed, which is true in the way that matters least to a notary who spent two weeks unable to work: the offline copies survived, while the production systems the country actually used did not. Dan Cimpean, who heads Romania’s National Cyber Security Directorate, offered the second statement. The attack was not complex, he said, and it exploited vulnerabilities his directorate had flagged to the agency shortly before the intrusion. A preventable attack, against a warned agency, still erased the working record of who owns Romania.

The Threat Model Reads One Way

Security engineers sort attacks into three buckets: confidentiality, integrity, and availability. Can someone read what they should not, change what they should not, or take away what you need? The legal profession has spent a decade building its entire cyber apparatus around the first bucket. Model Rule 1.6(c) requires reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, client information. Breach notification statutes trigger on exposure of personal data. Engagement letters warn about interception. Cyber insurance applications ask how well you keep secrets in. The lawyer’s mental model of a breach is a secret escaping.

Romania is the other two buckets. Nothing needed to escape for the damage to land. The attack destroyed the record itself and left an entire profession, the notariat, unable to work. A confidentiality lens applied to July 14 sees a data leak of moderate size. An integrity and availability lens sees a country that briefly could not prove who owned what.

Threat researchers have watched this shift build for two years. Extortion crews increasingly skip encryption entirely, stealing data and demanding payment against the threat of publication, and when the payment fails to arrive, some now escalate to destruction rather than walking away. Jake Williams, a faculty member at the security research firm IANS, described the Romanian incident as exactly that pattern: an extortion-only operation that turned destructive after negotiations collapsed. The refusal to pay, the advice every law enforcement agency gives, worked as designed. The attacker got nothing. The country still lost its registry for two weeks. Refusing the ransom is the right call, and it is not a defense.

The Rule Everyone Cites and Nobody Finishes Reading

American legal ethics anticipated this scenario, in a clause that gets skipped. ABA Formal Opinion 483, the 2018 opinion on lawyers’ obligations after a data breach, appears in every incident response memo for its notification duties. Its definition of a breach is broader than its reputation. The opinion covers events where material client information is misappropriated, destroyed, or otherwise compromised, and, separately, events where a lawyer’s ability to perform the legal services for which the lawyer was hired is significantly impaired. Destruction is in the text. Impairment is in the text. A wiper attack that erases your document management system triggers Formal Opinion 483 without a single secret leaving the building.

Destruction also implicates a rule that almost never appears in cybersecurity conversations: Model Rule 1.15, safekeeping property. Client files are client property. A firm whose matter files exist only as bits on a server an intruder can erase is holding client property in a vault with no walls. Rule 1.16(d) compounds the problem at the end of every representation, because it requires the lawyer to surrender papers and property the client is entitled to receive. You cannot surrender a file that no longer exists. Disciplinary exposure from a destructive attack runs through property rules the profession has never read as cyber rules. It does not stop at discipline. A firm that cannot produce the deal file when the client’s acquisition unravels into litigation faces a malpractice theory that writes itself, and Formal Opinion 483 layers a communication duty on top: clients get told, under Rule 1.4, when a breach involving their material information occurs. Telling a client someone read their file is an uncomfortable call. Telling a client their file is gone is a different conversation entirely.

It Already Happened Here

On the morning of October 12, 2023, Kyle Steadman, head of the litigation practice at Foulston Siefkin in Wichita, was preparing for a three-week jury trial when pleadings stopped going through. Within hours the Kansas Supreme Court announced that the statewide court system was down. Most of Kansas’s courts stayed offline for more than five weeks. Attorneys filed motions on paper and by fax while piles of documents grew that clerks would eventually have to sort and scan back into the record. Chris Joseph, a criminal defense attorney in Lawrence, described the effect with the weariness of a man watching a courthouse operate at hand-crank speed: it just slowed the whole system down. Clerks could not accept electronic payments. Officials later confirmed that a ransomware group had stolen data affecting roughly 150,000 people, and Chief Justice Marla Luckert told legislators the recovery would cost at least $2.6 million before notification and credit monitoring costs.

Kansas was not an outlier. Allan Liska of Recorded Future counted 18 state, city, or municipal court systems targeted by ransomware groups between 2019 and late 2023, including a Dallas attack that forced canceled jury trials. Three months after Kansas, in late January 2024, the LockBit ransomware group hit Fulton County, Georgia, taking down the phones, the tax systems, and the courts’ electronic filing in the county then prosecuting a former president. The gang’s teaser leak appeared to include sensitive and sealed records from criminal trials. Recovery stretched past a month. Each of these was an availability attack on a system of record, and each one forced lawyers to discover, in real time, exactly what their practice depends on.

North Carolina lawyers should feel this in the spine, because the state just finished concentrating the risk. Since February 2023, the Administrative Office of the Courts has been moving every county onto eCourts, a cloud-based case management platform built by Tyler Technologies under a contract worth roughly $100 million over ten years. By mid-2025, 73 counties were live, with the remainder scheduled to follow. That rollout produced its own record of what happens when a single system of record fails, no hacker required. Within four days of the Mecklenburg County launch, according to the federal judge who allowed a class action to proceed, 66 people sat in jail longer than they should have because of defects in the warrant repository and case management software. One plaintiff, Timia Chaplin, was rearrested in Wake County on charges dismissed nearly a month earlier. The litigation produced a reported settlement near $5 million in 2026, with no admission of liability. A defective register put handcuffs on people. A deleted one is not a smaller problem.

The Comfort, and the Hole in It

A fair objection exists here, and it deserves its strongest form. American property law is unusually resilient against the exact Romanian scenario. Romania, like most of Europe, runs a registration system: the register is the title. The United States runs recording systems, in which recorded documents are evidence of title rather than title itself, and a private industry, title insurance, exists precisely because American land records were never trusted to be complete or correct. Wipe a county recorder’s office, and the deeds in ten thousand safe deposit boxes, the closing files in a thousand law firms, and the title plants of the insurers still exist. That redundancy is cultural, built over two centuries of assuming the record might be wrong. Romania’s offline backups did their job, too. The system held.

The comfort is real, and it is narrow. Those resilience layers protect land title. They do not protect the systems your practice actually runs on. No title insurer reconstructs a court docket. No recording act restores your document management system, your billing history, or the privileged correspondence in a matter file. Kansas limped through five weeks because in 2023 paper remained a living option; clerks knew the old way and litigants tolerated it. North Carolina has now spent nine figures making sure the old way no longer exists. The profession is dismantling its analog redundancy at the exact moment attackers are adding deletion to the extortion playbook, and law firms hold the concentrated, well-labeled data that draws them. [See Why Hackers Target Law Firms, The Technology Blind Spot (2025).]

Thursday

Two checks, both executable this week. First, pull one closed transaction, a real estate closing or a corporate deal, and confirm your firm holds the file-stamped, recorded instruments as independent copies in your own files, not as bookmarks into the county’s or the court’s system. If your archive is a set of links into someone else’s database, you own an archive the way ANCPI’s users owned a land registry.

Second, put one question to whoever runs your backups, in writing: can the credentials that administer our production systems also reach our backup copies? A backup an administrator account can delete is not a backup; it is a second copy waiting for the same wipe. The answer you want involves the words offline or immutable, meaning a copy that no password, stolen or otherwise, can alter. ByteToBreach wiped everything his stolen password could touch. The copies that saved Romania were the ones it could not. Ziarul Financiar, the Romanian financial daily, reported that ANCPI spent 710 million lei, about 135 million euros, digitizing its operations over twenty years, and 0.2 percent of that amount, roughly 305,000 euros, securing them. Romania’s national cybersecurity directorate says it warned the agency about the specific vulnerabilities shortly before the attack. The distance between those two numbers is what your one question should surface before someone else surfaces it for you.

Ana Stan got her registry back because a copy existed beyond the reach of the person destroying it. Every breach conversation in this profession opens with the same reflexive question about who else can see the files. July 14 asks the better one. If someone deleted them tonight, would anyone, anywhere, still be able to read them at all?

About the Author

JD Morris is Co-Founder and COO of LexAxiom, an Agentic AI platform for the business of law. Over a 25-year career, he has built and scaled enterprise technology products across Dell, EMC, VMware, and Cisco, including the first exabyte eDiscovery platform. He holds dual MBAs from Columbia Business School (Finance) and UC Berkeley Haas (Marketing), a Master of Legal Studies in Cybersecurity Law from Texas A&M, and a Master of Engineering from George Washington University. He writes The Technology Blind Spot on the intersection of emerging technology and law. Connect with him on LinkedIn at www.linkedin.com/in/jdavidmorris, on X at @JDMorris_LTech, or on Bluesky at @JDMorris-ltech.bsky.social.

References

1. Model Rules of Pro. Conduct r. 1.6(c) (Am. Bar Ass’n 2024).

2. Model Rules of Pro. Conduct r. 1.15 (Am. Bar Ass’n 2024).

3. Model Rules of Pro. Conduct r. 1.16(d) (Am. Bar Ass’n 2024).

4. ABA Comm. on Ethics & Pro. Resp., Formal Op. 483 (2018).

5. Gintaras Radauskas, Hacker Wipes European Country’s Entire Land Registry Database, Paralyzing Real-Estate Market, Cybernews (July 20, 2026), https://cybernews.com/security/hacker-deletes-romanian-land-registry-database/.

6. Risky Bulletin: Hacker Wipes Romania’s Entire Land Registry Database, Risky Bus. News (July 20, 2026), https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database/.

7. Romania’s Real Estate Market Still Reeling from Major Cyberattack Against Land Registration Agency, Romania Insider (last visited July 30, 2026), https://www.romania-insider.com/romania-real-estate-cyberattack-land-registration-2026.

8. Land Registry Cyberattack Exposes Holes in Romania’s Digital Defences, Balkan Insight (July 21, 2026), https://balkaninsight.com/2026/07/21/land-registry-cyberattack-exposes-holes-in-romanias-digital-defences/bi/.

9. A Hacker Stole Romania’s Entire Land Registry Database, Then Deleted It, IANS Rsch. (July 22, 2026), https://www.iansresearch.com/resources/all-blogs/post/security-blog/2026/07/22/a-hacker-stole-romania-s-entire-land-registry-database—then-deleted-it.

10. Associated Press, Kansas Court System Down Nearly 2 Weeks in ‘Security Incident’ That Has Hallmarks of Ransomware (Oct. 25, 2023).

11. Associated Press, Kansas Officials Blame 5-Week Disruption of Court System on ‘Sophisticated Foreign Cyberattack’ (Nov. 21, 2023).

12. Associated Press, Kansas Courts Need at Least $2.6 Million to Recover from Cyberattack, Official Says (Jan. 16, 2024).

13. Brian Krebs, Fulton County, Security Experts Call LockBit’s Bluff, KrebsOnSecurity (Feb. 29, 2024), https://krebsonsecurity.com/2024/02/fulton-county-security-experts-call-lockbits-bluff/.

14. eCourts’ Continuing Legal Mess, The Assembly (Apr. 4, 2025), https://www.theassemblync.com/politics/courts/ecourts-north-carolina-lawsuit/.

15. Possible Settlement in eCourts Lawsuit, The Assembly (June 8, 2026), https://www.theassemblync.com/news/politics/justice/ecourts-north-carolina-lawsuit-settlement/.

16. State and Local Courts Struggle to Fight Increasing Cyberattacks, State Ct. Rep. (last visited July 30, 2026), https://statecourtreport.org/our-work/analysis-opinion/state-and-local-courts-struggle-fight-increasing-cyberattacks.



Originally published on LinkedIn Newsletter — The Technology Blind Spot

Leave a Reply

Discover more from The Technology Blind Spot

Subscribe now to keep reading and get access to the full archive.

Continue reading