An update from the land registry (the truthfulness of this remains to be seen depending on how fast this comes back online):
ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.
After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.
ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.
According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.
The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.
The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.
My ex was late from work once a week because the company did commercial real estate logistics (sort of similar domain here) and she had the job of going to the secure data center and grabbing a backup disk out of the cage and transferring it to a safety deposit box.
The dumb thing was the bank was two blocks from the data center and less than eight (six?) from the office so catastrophic events might have hit both or all three. The owner kept a second copy at his house, and that was the only geographically separated copy.
Yes, quite, this.
One of the lessons (and subsequent data integrition / continuity of business practices) learned from the 9/11 attacks in New York City, and destruction of both primary and secondary data stores of multiple entities (as well as several emergency-response agencies at various government levels from city to federal) was that essential data and operational roles need to be redundant across very widely-separated locations.
E.g.: from "Discussion note prepared by staffs of the Federal Reserve, the New York State Banking Department, the Office of the Comptroller of the Currency, and the Securities and Exchange Commission, for discussion at a meeting on February 26, 2002 at the Federal Reserve Bank of New York":
[I]t was clear that business continuity planning had not fully taken into account the potential for wide-area disasters and for major loss or inaccessibility of critical staff. Contingency planning at many institutions generally focused on problems with a single building or system. Some firms arranged for their backup facilities to be in nearby buildings on the assumption that, for example, a fire might incapacitate or destroy a single facility. Very few planned for an emergency disrupting an entire business district, city, or region. As a result, some firms lost access to both their primary and backup facilities in the aftermath of the September 11 events, severely disrupting their operations.
"Summary of "Lessons Learned" from Events of September 11 and Implications for Business Continuity" February 13, 2002" <https://www.sec.gov/divisions/marketreg/lessonslearned.htm>
Geographic distances were rarely considered prior to 9/11. Most companies were comfortable replicating data intercampus or to a facility within a few miles of a primary data center. A few firms, such as Nasdaq, actually replicated data out of state.
"9/11: Top lessons learned for disaster recovery" (Sep 9, 2011) <https://www.computerworld.com/article/1545389/9-11-top-lesso...>
Also: "Hard-Earned Disaster Recovery Lessons From 9/11 and other disasters" (2025) <https://backupcentral.com/hard-earned-disaster-recovery-less...>
Terrorist attacks, natural disasters, widespread power and other failures, etc., can all have impacts across many kilometres, possibly many hundreds. Redundancy equates to survivability here.
More broadly, information and data services are fundamentally about risk management and disaster response, as realised during 9/11 (as well as multiple earlier and subsequent incidents) in ways which weren't fully realised at the turn of the millennium. Or even today in some organisations.
Make backups. Test backups. Practice switchovers between primary and secondary (or multiple redundant) operations. And keep those resources and facilities widely separated.
>it had begun migrating its applications to Romania’s Government Cloud
This proclamation, coming from a governmental organization, makes me afraid they are doomed. Effectively they are saying they are fixing the mistake by repeating it.
What they should do is admit fault. Freeze the system. Get independent expert help.
Best wishes, recent Romanian land buyers and sellers
Edit: thank you @cbg0 for giving us this update
They are getting expert help. I expect that the agency maintained their own local deployment on infra administered by its own employees. Now they are migrating to the central 'government(-maintained) cloud'.
At the same time they are working with authorities.
Not everything needs an external consultant.
Your prejudice knows no bounds.