The cyber threat group known as Bytetobreach has expanded its operations into Romania, targeting the National Agency for Cadastre and Land Registration (ANCPI) shortly after a major breach at Latvia’s state-owned forestry company, Latvijas Valsts meži (LVM).
The Latvian Computer Emergency Response Team (Cert.lv) confirmed it is assisting Romanian counterparts in investigating the incident, which involves the same actor responsible for the June data leak at LVM.
Bytetobreach publicly claimed responsibility for the attack on Romania’s land registry last week.
The group had previously made headlines in June when it compromised LVM’s servers, resulting in a significant data breach that drew regional attention.
The connection between the two incidents suggests a coordinated campaign by the group against public sector and state-owned entities in the Baltic and Eastern European regions.
The attack on ANCPI has disrupted the agency’s IT systems, with stolen data reportedly listed for sale online.