STAT / DIGITAL
Menu

Evidence and sources

The evidence behind the analysis

This page brings together the documents and data supporting the analysis: 25 selected cases and campaigns, institutional powers, legislation, the Government Cloud, international comparisons, methodology and the complete source library.

Back to the analysis

Selective timeline

What we know about an incident changes over time

The first statement, technical confirmation, investigation and later consequences do not arrive at once. The dossier preserves the timeline and the contradictions, not only the first figure published.

How the timeline was assembled

Cases and campaigns selected for the patterns they illustrate; this is not an exhaustive register of incidents in Romania.

Included

  • Romanian public entity, state-owned company or supplier with documented public-sector impact
  • at least one verifiable public source
  • enough information to separate documented facts from unknowns
  • explanatory value for a recurring pattern

Excluded

  • rumours and uncorroborated claims
  • exposed vulnerabilities without evidence of an incident
  • duplicates and reports lacking verifiable information
  • classified systems without sufficient public information

Timeline filters

25 records shown

Cases were selected for explanatory value and verifiable public sourcing. The number is not the total of Romanian incidents. DDoS can block access without compromising data; defacement may affect only a public interface.

IncidentStatusPublicly confirmed incidentSource shownSecondary reporting attributing confirmation to the institutionLatest public status

Romanian Police public interface

What is publicly documented
An unauthorised message appeared on the website. Police said only the public interface, separate from operational databases, was affected.
Still unknown
The vector and extent of administrative access.
What changed or followed
Police said the operational databases were separated from the public interface and were not affected.
IncidentStatusCredibly reportedSource shownSecondary reportingLatest public status

Sector 1 City Hall

What is publicly documented
The information system was blocked, digital citizen services became unavailable and the city hall referred the case to DIICOT.
Still unknown
The vector, data access, exact duration and recovery outcome.
What changed or followed
Citizens were redirected to physical counters; no public technical postmortem was identified.
CampaignStatusPublicly confirmed incidentSource shownPrimary source availableLatest public status

APT28 attempt against a government institution

What is publicly documented
SRI announced it had stopped a spear-phishing attempt probably linked to APT28. The attack caused no damage.
Still unknown
The targeted institution and operational objective were not disclosed.
What changed or followed
SRI published details of the attempt and said it was countered without damage.
IncidentStatusPublicly confirmed incidentSource shownSecondary reporting attributing confirmation to the institutionLatest public status

Four hospitals hit by ransomware

What is publicly documented
CERT-RO and partners investigated incidents at four hospitals. Later analysis pointed to the Maoloa and Phobos families.
Still unknown
The full service, data and recovery impact for each facility.
What changed or followed
Recommendations covered antivirus, RDP, updates and offline backups.
IncidentStatusCredibly reportedSource shownSecondary reportingLatest public status

Oradea City Hall

What is publicly documented
Ransomware encrypted part of the data and blocked the document management system. City Hall said the data would be fully recovered from backup.
Still unknown
The vector, actual restoration time, exfiltration and prior backup testing.
What changed or followed
Some counter services were suspended until restoration.
IncidentStatusPublicly confirmed incidentSource shownPrimary source availableLatest public status

Witting Hospital

What is publicly documented
PHOBOS encrypted servers and attackers demanded a ransom. The hospital continued with offline registers and did not pay.
Still unknown
Recovery duration, data loss and verification of remediation.
What changed or followed
SRI published urgent technical recommendations to contain and prevent similar incidents.
IncidentStatusPublicly confirmed incidentSource shownPrimary source availableLatest public status

A faculty platform at Politehnica Bucharest

What is publicly documented
User lists and, for some students, national identification numbers were extracted. The university said its central database was not accessed.
Still unknown
The number of people, the vector and how long the vulnerability existed.
What changed or followed
The issue was remediated the same day and the authorities were notified.
CampaignStatusPublicly confirmed incidentSource shownPrimary source availableLatest public status

Killnet-claimed DDoS wave

What is publicly documented
Websites belonging to authorities and financial institutions were unavailable for several hours.
Still unknown
The precise cost and duration for each service.
What changed or followed
SRI said the affected sites were outside the TITEICA protection system.
IncidentStatusPublicly confirmed incidentSource shownSecondary reporting attributing confirmation to the institutionLatest public status

Education Ministry website

What is publicly documented
An unauthorised message replaced the public page. The ministry took the site offline for assessment, isolation and remediation and said the platform held no confidential data.
Still unknown
The vector, administrative access and the security audit findings.
What changed or followed
The website infrastructure was hardened before restoration.
IncidentStatusIncluded in an official reportSource shownSecondary reporting attributing confirmation to the institutionLatest public status

National disability management system

What is publicly documented
DNSC's annual report included the compromise of the National Disability Management System infrastructure.
Still unknown
The exact date, impact on beneficiaries, data, duration and recovery.
What changed or followed
Public information remains limited to the annual summary.
IncidentStatusPublicly confirmed incidentSource shownSecondary reporting attributing confirmation to the institutionLatest public statusConflicting public figures

Chamber of Deputies

What is publicly documented
The attack and the exfiltration of some documents were publicly confirmed. The official figures subsequently communicated do not agree: the digitalisation minister initially referred to about 250 GB, while a later statement attributed to DNSC referred to 316 files totalling about 300 MB.
Still unknown
We did not identify a public technical report reconciling the two figures, describing the full extracted dataset or explaining whether they measure different things. The initial vector, the number of affected people and the outcome of the criminal investigation also remain insufficiently documented in public.
What changed or followed
The Chamber of Deputies later announced restrictions on access to certain services and platforms. We did not identify a consolidated public technical postmortem.
IncidentStatusPublicly confirmed incidentSource shownPrimary and secondary sourcesLatest public status

The Hipocrate platform and 26 hospitals

What is publicly documented
Backmydata ransomware, from the Phobos family, encrypted servers running a shared platform. DNSC's final count reached 26 hospitals and about one week of disruption.
Still unknown
Exfiltration, the initially failed control, final data loss and cost.
What changed or followed
Malware analysis, YARA rules and distributed recommendations; recovery is not consolidated in one public report.
IncidentStatusPublicly confirmed incidentSource shownPrimary and secondary sourcesLatest public status

Timisoara City Hall, Tax Directorate and Local Police

What is publicly documented
Online services were affected and DNSC later reported about 112 systems. Critical data and part of the non-critical data were recovered.
Still unknown
The vector, accessed data and full recovery time.
What changed or followed
Public services returned gradually; no public technical postmortem identified.
IncidentStatusPublicly confirmed incidentSource shownPrimary and secondary sourcesLatest public status

Sector 5 City Hall

What is publicly documented
Domain controllers, workstations and the Local Police telephone exchange were affected. Attackers demanded 5 million dollars.
Still unknown
Exfiltration, backups, system count and final recovery.
What changed or followed
New measures were promised, without a unified public record of implementation.
IncidentStatusPublicly confirmed incidentSource shownPrimary and secondary sourcesLatest public status

Electrica Group

What is publicly documented
Power distribution and supply continued and critical systems were declared unaffected. DNSC reported more than 800 servers and 4,000 workstations affected in corporate IT.
Still unknown
The vector, exfiltration, cost and complete recovery outcome.
What changed or followed
The company reported restoration and continuity measures. A sector response centre for energy was later provided for in government documents; the sources do not establish the Electrica incident as the sole cause.
Supplier eventStatusPartially confirmedSource shownPrimary source availableLatest public status

Orange incident and data linked to public clients

What is publicly documented
Orange confirmed that a ticket-resolution application was attacked and that categories of data belonging to some YOXO customers were extracted. DNSC said its preliminary analysis also identified legal persons, including public institutions, municipalities, schools and hospitals. Orange network services were not reported affected.
Still unknown
The list of institutions, the exact data associated with each and any direct compromise of those customers’ systems have not been published.
What changed or followed
Orange announced additional security measures; DNSC continued its analysis. No complete public postmortem was identified.
IncidentStatusPublicly confirmed incidentSource shownSecondary reporting attributing confirmation to the institutionLatest public status

Iași County Council Facebook page

What is publicly documented
An administrator account was taken over without authorisation and the institution lost control of an official communication channel.
Still unknown
The compromise method, whether MFA was enabled and the exact access period.
What changed or followed
The institution worked with Meta on recovery and moved communication to alternative channels.
IncidentStatusCredibly reportedSource shownSecondary reportingLatest public status

Orăștie City Hall

What is publicly documented
Files on two servers and one computer were encrypted across accounting, taxes, human resources and other functions; attackers demanded about EUR 26,000.
Still unknown
Exfiltration, backup quality, duration and the final recovery result.
What changed or followed
The local administration reported the case; no final public technical account was identified.
IncidentStatusPublicly confirmed incidentSource shownPrimary source availableLatest public status

Romanian Waters and 10 basin administrations

What is publicly documented
About 1,000 IT and communications systems at the Romanian Waters Administration were compromised, including GIS, databases, servers and workstations. Operational technology remained unaffected.
Still unknown
The vector, exfiltration, cost and point of full recovery.
What changed or followed
Operational systems were not reported affected. Public sources do not identify which control limited the impact.
IncidentStatusPublicly confirmed incidentSource shownPrimary source availableLatest public status

CONPET

What is publicly documented
The attack affected business IT infrastructure and the company website. SCADA and operational telecommunications remained unaffected and oil transport continued.
Still unknown
The vector, accessed data, the scope of affected systems and full recovery.
What changed or followed
CONPET worked with the authorities and filed a criminal complaint with DIICOT.
IncidentStatusPublicly confirmed incidentSource shownPrimary source availableLatest public status

eViza and eConsulat

What is publicly documented
The Foreign Ministry reported a DDoS attack against eViza and eConsulat on 13–14 March. The platforms slowed down and were briefly unavailable, then returned to normal operation. The ministry said no sensitive information was accessed.
Still unknown
The actor and malicious traffic volume were not published.
What changed or followed
Protective equipment and ministry specialists reduced the impact. No intrusion was reported.
CampaignStatusPublicly confirmed incidentSource shownPrimary source availableLatest public status

Operation Masquerade

What is publicly documented
SRI joined the disruption of a router infrastructure used by APT28. Romanian entities, including government, military and critical sectors, were compromised in the global campaign.
Still unknown
The Romanian victims, access duration and losses.
What changed or followed
The attack infrastructure was disrupted; recommendations covered unsupported routers and firewall rules.
IncidentStatusUnder investigationSource shownPrimary source availableOngoing

ANCPI and e-Terra

What is publicly documented
ANCPI confirmed the largest technical disruption in its history. In its 20 July update, the institution said that its technical and legal databases were not affected and that application migration to the Government Cloud had begun under STS coordination, with completion estimated for 22 July. Checks and a report were to follow; no date for phased service restoration had yet been announced.
Still unknown
The vector, persistence, access scope, exfiltration, the final amount of copied data, backup integrity and isolation, the proportion restored and the final recovery time.
What changed or followed
ANCPI estimates completion of application migration on 22 July. This is not the service-restart date: applications and data are to be checked, and the resulting report will inform a timetable for phased restart. ANCPI’s statement that the technical and legal databases were not affected does not replace an independent public technical report.
IncidentStatusUnder investigationSource shownPrimary source availableOngoing

MIPE — Private Beneficiaries Procurement

What is publicly documented
MIPE announced that the application used for procurement by private beneficiaries of cohesion projects had been targeted in a cyber incident and was inaccessible. Competent authorities were notified and teams were analysing and restoring the service.
Still unknown
The vector, duration, affected data, any exfiltration and the recovery mechanism had not been published by the verification date.
What changed or followed
By 20 July 2026, we had found no public update later than the statement of 16 July. The latest public position found said the incident was under analysis and the application was being restored.
IncidentStatusUnder investigationSource shownPrimary and secondary sourcesOngoing

Brașov Fiscal Directorate

What is publicly documented
Brașov City Hall says that the server hosting the Fiscal Directorate website was targeted by Trojan malware. The server was temporarily disconnected to limit the effects, making the website unavailable.
Still unknown
The initial vector, technical confirmation of the malware type, access beyond the web server, any access to data and the restart date.
What changed or followed
The institution says it is identifying the causes and carrying out remediation. Server isolation is documented as a containment measure; the investigation outcome and full recovery are not yet public.

The power map

“Who is responsible?” has a different answer for each operation

Choose an action. The institutions remain, but the primary role, control and limit change.

Choose an action to see how responsibility is distributed
01

Who can see what exists?

Institution

Inventories its assets and risks; remains accountable for accuracy.

DNSC

Can demand relevant asset lists and evidence during supervision.

ADR / PNIDP

Will operate the national inventory after entry into force and population.

Current limit

The PNIDP law enters into force on 3 January 2027; the national inventory is not yet operational. Automated links to technical sources remain decisive.

All operations without interaction

Who can see what exists?

Institution: Inventories its assets and risks; remains accountable for accuracy.

DNSC: Can demand relevant asset lists and evidence during supervision.

ADR / PNIDP: Will operate the national inventory after entry into force and population.

Current limit: The PNIDP law enters into force on 3 January 2027; the national inventory is not yet operational. Automated links to technical sources remain decisive.

Who allows production use?

Institution: Retains accountability for the service and makes the operational decision to launch or keep it running. That accountability is not, in every case, equivalent to a formal, time-limited and publicly traceable acceptance of risk.

SRI: For SaaS services in the Private Government Cloud, participates in assessment, tests security and approves production launch from a cybersecurity perspective.

STS: Within the Private Government Cloud, can block IaaS/PaaS resources that endanger the platform.

Current limit: The gate exists in the cloud but not as a uniform regime for every critical public service.

Who compels remediation?

DNSC: Supervises, imposes plans, owners and deadlines, then verifies remediation evidence.

Sector authority: Can supervise and sanction within its sector and coordinates with DNSC.

Entity leadership: Approves measures, allocates resources and is accountable for breaches.

Current limit: There is no public dashboard of active plans, missed deadlines, retesting and case closure.

Who can isolate danger?

Institution: Can stop its own service and remains responsible for continuity.

SRI / STS: Have technical isolation powers inside the private government cloud perimeter.

DNSC: Can order preventive measures and the cessation of non-compliant conduct.

Current limit: The institution can stop its own service, and DNSC can impose measures and the cessation of non-compliant conduct. The reform proposal is an explicit, rapid cross-government procedure for temporary isolation in cases of severe risk, with continuity safeguards and legal review.

Who follows the data breach?

Institution / DPO: Assesses risk, notifies and informs people when required.

ANSPDCP: Investigates GDPR compliance and can impose a warning, remediation plan, follow-up control and fine.

DNSC: Handles the cyber security and significant incident dimension.

Current limit: The two supervisory tracks are not publicly consolidated into one incident and remediation record.

Selected legal framework

Law covers many stages. A persistent service identity must connect them.

The analysis mainly concerns civilian national cyberspace and public administration. Defence, public order, national security and classified information may have separate regimes.

Audit scope

The audit examined the legality of a 2025 legal-consultancy contract. It did not assess incident response, technical analysis or operational cyber-security capacity.

Finding

The Court issued an adverse conclusion: non-compliance was generalised. It identified procurement without the required approval, duplication of in-house legal duties, formalistic preventive financial control and no approved procurement procedures.

RON 24,475.20 paid in 2025

A partial model already visible

The government cloud separates migration, assessment and audit

Government Cloud procurement documents separate three functions that should not be confused: a supplier moves the application, an evaluator looks for vulnerabilities, and an auditor independently checks whether the stages and controls existed.

Together, the three procedures describe a control chain: one team moves the application, another tests its security, and a third independently checks whether migration and assessment were performed. None of these stages can replace another.

International models

Other states connect the pieces in different ways

France, the United States, the United Kingdom, Estonia and Germany use different mechanisms. The comparison asks who defines architecture, who checks security, how operation is authorised and who can demand measurable action.

CountryDigital architectureCyber authorityInventoryAuthorisationDirectivesStopping and accountabilityLimit / trade-off
FranceDINUMANSSIGovernment registers and doctrineHomologation: a named authority accepts risk for a fixed periodDoctrine and mandatory requirements in defined perimetersThe decision depends on the homologation authority and competent operatorsThe process can be resource-intensive and does not remove the need for monitoring between homologations.
United StatesFederal CIO / OMBCISAAutomated discovery and federal visibility in covered civilian agenciesNIST RMF: an authorising official decides whether risk is acceptable; continuous monitoring informs the decisionBinding Operational Directives and Emergency Directives with concrete deadlinesCISA and agencies act within the civilian federal framework; national-security systems have separate regimesThe federal model does not apply uniformly across every level of government and does not mean universal continuous authorisation.
United KingdomGovernment Digital ServiceNCSC / Government Security GroupInitiative pipeline and continuous monitoring of exposed assets for thousands of public bodiesFrom April 2026, organisations conduct most assurance and approvals; GDS supports complex and risky initiativesShared standards, GovAssure and the Digital Assurance Playbook; former spend controls were removedAccounting Officers and service owners retain accountability; the centre tracks major risksDevolution assumes uneven maturity and sufficiently strong internal assurance teams.
EstoniaGovernment CIO functionRIARIHA links systems, owners and changesRIHA procedures and E-ITS auditE-ITS provides concrete controls and proportional auditRIA and owners act within the Estonian legal frameworkScale and administrative architecture differ from Romania; transfer requires shared services for small institutions.
GermanyFederal CIO / federal ministriesBSIFederal tools and registers in a system fragmented between federal and state levelsIT-Grundschutz and security audits for federal administrationBSI sets standards and supports audits within its remitPowers vary by level and legal regimeFederalism produces the same fragmentation problem the model is designed to manage.

Reform proposal

A service passport, two technical keys and one risk owner

An architecture function coordinates the portfolio and standards. DNSC verifies independently. Institutional leadership formally accepts risk for a limited period. These roles check one another.

RO / SERVICE

Service passport

  1. 01service, system, data, continuity and contract owners
  2. 02criticality, RTO, RPO and degraded mode
  3. 03assets, versions, support, domains, certificates and APIs
  4. 04suppliers, subcontractors and privileged access
  5. 05assessments, audits, remediation and retesting
  6. 06backup, last restoration and clean recovery environment
  7. 07accepted risks, exceptions and expiry date
  8. 08history of changes, incidents and authorisations
A

Architecture key

A strengthened ADR or equivalent Government CTO function: standards, PNIDP, shared platforms, portfolio, spend controls and removal of unsupported technology.

B

Safety key

Independent DNSC: supervision, audit, directives, deadlines, scanning, remediation verification, managed suppliers and urgent isolation under defined conditions.

C

Proposed risk-acceptance mechanism

Under the model proposed in this analysis, institutional leadership signs a time-limited decision on continued operation. An incident, expiry or material change reopens the assessment.

01

Centralisation can create a single point of failure

Standards and estate visibility can be shared without one institution operating every application. Separating architecture from supervision reduces self-certification.

02

Stopping a service can harm essential delivery

The proposed procedure should prefer minimum isolation, degraded mode and short duration, with explicit continuity ownership.

03

Transparency can expose infrastructure

The public needs indicators and decisions, not IP addresses, live vulnerabilities or exploitable architecture. Passport access must be tiered.

04

Small municipalities cannot implement every control alone

Shared scanning, privileged identity, backup and response services reduce burden and standardise evidence.

05

A new register can become a static form

PNIDP’s value will come from automated reconciliation with DNS, cloud, identity, code, vulnerabilities and contracts, plus owners accountable for discrepancies.

06

The main cost is human capability

PAM, EDR and scanning can be bought. The state also needs people who can define architecture, challenge suppliers, read evidence and accept risk.

01

Critical services with a named owner

Definition
A service for which service, system, data, continuity and contract ownership is approved.
Numerator / denominator
critical services with every role completed / all critical services in the reporting universe
Owner
institutions / ADR
Frequency
quarterly
Target
100% after inventory
Caveat
individual names may remain non-public; the percentage can be published in aggregate
02

Automatically discovered and reconciled assets

Definition
Technically observed assets that have an inventory record and owner.
Numerator / denominator
reconciled assets / automatically discovered assets
Owner
ADR + institutions
Frequency
monthly
Target
≥95%
Caveat
granular publication can create risk; publish distributions and trends
03

Internet-exposed management interfaces

Definition
Management consoles directly reachable from the internet without an approved intermediary control.
Numerator / denominator
open non-compliant interfaces / identified management interfaces
Owner
DNSC + institutions
Frequency
continuous / quarterly report
Target
0 non-compliant after deadline
Caveat
temporary exceptions must be documented and expire
04

Privileged accounts with phishing-resistant MFA and PAM

Definition
Named administrative accounts protected and managed through privileged-access controls.
Numerator / denominator
compliant accounts / all active privileged accounts
Owner
institutions
Frequency
monthly
Target
≥95%, then 100% for critical systems
Caveat
break-glass accounts need separate procedures and audit
05

Exploited vulnerabilities remaining after deadline

Definition
Known-exploited vulnerabilities not remediated or compensated by the required deadline.
Numerator / denominator
overdue vulnerabilities / all identified exploited vulnerabilities
Owner
DNSC + institutions
Frequency
weekly / monthly report
Target
0 overdue without a valid exception
Caveat
technical details are not published per system
06

Successful restoration tests

Definition
Services for which a backup restoration was executed and validated in the reporting period.
Numerator / denominator
services with a successful test / services requiring backup and recovery
Owner
institutions
Frequency
semi-annually or by criticality
Target
100% according to cadence
Caveat
the existence of a backup does not prove restorability
07

Proposal: services with a valid operating decision

Definition
A proposed indicator for critical services whose assessment and formal risk acceptance have not expired or been invalidated by material change.
Numerator / denominator
services with a valid decision / critical services subject to the regime
Owner
institutions + assurance authority
Frequency
continuous / quarterly report
Target
100%
Caveat
proposed indicator; the uniform regime does not yet exist
08

Public post-incident reports

Definition
Major incidents with a public summary after the investigation stabilises.
Numerator / denominator
incidents with a public report / eligible major incidents
Owner
institutions + DNSC
Frequency
annual
Target
100%, with reasoned exceptions
Caveat
the report must protect operational and personal data

Method and sources

How the evidence is handled

Each entry shows what is publicly documented, what remains unknown and which sources support the statement. Incidents, campaigns and supplier events are counted separately.

Publicly documentedAn institution, authority, court record or identifiable report supports the claim.Ongoing investigationFacts may change; unknowns remain visible beside the claim.InferenceAn analytical conclusion is separated from documented facts.ProposalA recommended solution, not an existing power or institution.

What the evidence can and cannot show

  • The timeline is selective. It brings together cases with public sources that reveal a mechanism; it does not claim to count every incident in Romania.
  • Some reports and technical evidence are confidential. Their absence from public view does not prove that institutions lack internal controls or information.
  • Procurement figures describe procedures and contracts. They do not by themselves prove that an application was accepted, tested and placed in production.
  • The Court of Accounts audit concerns a legal-consultancy procurement and the administrative controls around it. It does not assess DNSC’s technical incident-response capacity.

Author and editor

Marius Comper

Corrections and contact

statdigital [at] mariuscomper [dot] uk

Verified through

Published data licence

CC BY 4.0

No trackers; filter preferences remain only in the URL.

Glossary

17
CTE
Technical-Economic Committee for the Information Society
PNIDP
National Public Digital Infrastructure Platform
MAS IC
the project for migrating applications and information systems to cloud
IaaS
infrastructure as a service
PaaS
platform as a service
SaaS
software as a service
PAM
privileged access management
MFA
multi-factor authentication
SOC
security operations centre
SIEM
platform for correlating logs and alerts
SBOM
software bill of materials
RTO
recovery time objective
RPO
recovery point objective
ATO
formal authority-to-operate decision
BOD
binding operational directive issued by CISA
RIHA
Estonian information-system administration system
E-ITS
Estonian information security standard

Sources

62 sources

Primary source

Government Decision 941/2013 and the CTE framework

Portal Legislativ · 2013-11-27

Open source

Primary source

Romanian Intelligence Service: the APT28 attempt of 12 May 2017

Romanian Intelligence Service · 2017-05-12

Open source

Primary source

General Secretariat Order 600/2018 on internal managerial control

Portal Legislativ · 2018-04-20

Open source

Primary source

Law 190/2018, the regime applicable to public authorities

Portal Legislativ · 2018-07-18

Open source

Primary source

Romanian Intelligence Service: PHOBOS ransomware at Witting Hospital

Romanian Intelligence Service · 2021-07-20

Open source

Primary source

Romanian Intelligence Service: the DDoS attacks of 29 April 2022

Romanian Intelligence Service · 2022-04-29

Open source

Primary source

Emergency Ordinance 89/2022 on the Government Cloud

Portal Legislativ · 2022-06-27

Open source

Primary source

Law 242/2022 on interoperability

Portal Legislativ · 2022-07-20

Open source

Primary source

CISA BOD 23-01 — asset visibility and vulnerability detection

CISA · 2022-10-03

Open source

Primary source

Government Decision no. 112/2023 on Private Government Cloud governance

Portal Legislativ · 2023-02-08

Open source

Primary source

CISA BOD 23-02 — internet-exposed management interfaces

CISA · 2023-06-13

Open source

Primary source

Romanian Health Ministry: the Hipocrate ransomware incident

Romanian Ministry of Health · 2024-02-12

Open source

Primary source

Timișoara City Hall: statement of 26 August 2024

Timișoara City Hall · 2024-08-26

Open source

Primary source

Electrica: Bucharest Stock Exchange report of 9 December 2024

Bucharest Stock Exchange / Electrica · 2024-12-09

Open source

Primary source

Emergency Ordinance no. 155/2024, consolidated to 6 July 2026

Portal Legislativ · 2024-12-30

Open source

Primary source

Orange Romania — confirmation of an incident in a ticketing application

Orange Romania · 2025-02-28

Open source

Primary source

DNSC: statement on the Orange Romania incident of 23 February 2025

DNSC · 2025-03-04

Open source

Primary source

Law no. 124 of 7 July 2025

Portal Legislativ · 2025-07-07

Open source

Primary source

DNSC Order no. 3/2025 and supervision rules

Portal Legislativ · 2025-11-27

Open source

Primary source

Romanian Waters Administration: statement of 21 December 2025

Romanian Waters Administration, via AGERPRES · 2025-12-21

Open source

Primary source

Government Digital Service: the UK government’s digital centre

GOV.UK · 2026

Open source

Primary source

UK Vulnerability Monitoring Service

GOV.UK · 2026-02-26

Open source

Primary source

Romanian Ministry of Foreign Affairs — DDoS attack on eViza and eConsulat

Romanian Ministry of Foreign Affairs, via AGERPRES · 2026-03-14

Open source

Primary source

Digital Assurance Playbook, effective from 1 April 2026

GOV.UK · 2026-04-01

Open source

Primary source

Romanian Court of Accounts: ad-hoc compliance audit at DNSC, no. 28536/16 April 2026

Romanian Court of Accounts · 2026-04-16

The audit concerns a 2025 legal-consultancy contract, not DNSC’s operational cyber capability.

Open source

Primary source

Law no. 119/2026 on PNIDP

Portal Legislativ · 2026-07-03

Open source

Primary source

Law no. 123/2026 on vulnerability research

Portal Legislativ · 2026-07-03

Open source

Primary source

ANCPI — statement of 15 July 2026

National Agency for Cadastre and Land Registration, via AGERPRES · 2026-07-15

Open source

Primary source

Romanian Ministry of Investments and European Projects — incident affecting the Private Beneficiaries Procurement application

Romanian Ministry of Investments and European Projects, via AGERPRES · 2026-07-16

Open source

Primary source

ANCPI — 20 July 2026 update on application migration and verification

National Agency for Cadastre and Land Registration · 2026-07-20

ANCPI says that its technical and legal databases were not affected and estimates completion of application migration to the Government Cloud on 22 July. A service-restart date was to be communicated only after checks and a report. These are institutional statements, not independent technical findings.

Open source

Primary source

Brașov City Hall — cyber incident affecting the Fiscal Directorate website

Brașov City Hall · 2026-07-20

City Hall says that the server hosting the Fiscal Directorate website was targeted by Trojan malware and disconnected to limit the effects. The malware classification and incident scope have not been independently verified.

Open source

Primary source

ADR, Technical-Economic Committee for the Information Society

Authority for the Digitalisation of Romania · publication date not stated

Open source

Primary source

ANCPI — outage, restoration and investigation updates checked on 19–20 July 2026

National Agency for Cadastre and Land Registration · publication date not stated

The ANCPI homepage is mutable. The detailed statement retained on 19 July records phased restoration, open investigations and the statement that several backup locations existed. The indexed observation from 20 July records that services remained unavailable while investigation and remediation continued. Declared locations do not prove restorability.

Open source

Primary source

ANSSI, security accreditation (homologation de sécurité)

ANSSI · publication date not stated

Open source

Primary source

BSI: IT security audits for Germany’s federal administration

BSI · publication date not stated

Open source

Primary source

CONPET: Bucharest Stock Exchange report on the February 2026 attack

CONPET, via the Bucharest Stock Exchange · publication date not stated

Open source

Primary source

DINUM, France’s interministerial digital directorate

Direction interministérielle du numérique · publication date not stated

Open source

Primary source

Estonia, E-ITS

Estonian Information System Authority (RIA) · publication date not stated

Open source

Primary source

Estonia, RIHA

Estonian Information System Authority (RIA) · publication date not stated

Open source

Primary source

GovAssure

UK Government Security · publication date not stated

Open source

Primary source

NIST Risk Management Framework: Authorize step

NIST · publication date not stated

Open source

Primary source

Romanian Intelligence Service: Operation Masquerade

Romanian Intelligence Service · publication date not stated

Open source

Primary source

Sector 5 City Hall: statement on the ransomware incident

Sector 5 City Hall · publication date not stated

Open source

Primary source

UK Government Cyber Security Standard

GOV.UK · publication date not stated

Open source

Primary source

University Politehnica of Bucharest: statement on the September 2021 incident

University Politehnica of Bucharest · publication date not stated

Open source

Public procurement catalogue

SICAP.ai — CN1077543, application migration services for the Private Government Cloud

SICAP.ai — public procurement catalogue · 2025-02-05

CN1077543 / CAN1155065

The link leads to a public catalogue reproducing procurement data. The identifiers can be used to find the official notice in SICAP.

Open source

Public procurement catalogue

SICAP.ai — CN1088688, technical and financial audit for MAS IC

SICAP.ai — public procurement catalogue · 2025-12-26

CN1088688 / CAN1168520

The technical audit checks the migration and the existence of security assessments; the specification explicitly excludes penetration testing and vulnerability assessment.

Open source

Public procurement catalogue

SICAP.pro — CN1083774, security assessment of migrated applications

SICAP.pro — public procurement catalogue · 2026

CN1083774

The procurement describes the required assessments; its existence does not prove that the assessments have already been performed.

Open source

Secondary source

Romanian Police: September 2014 public-interface incident, contemporaneous report

Știrile ProTV · 2014-09-19

The report quotes Romanian Police on the separation of the public interface from operational databases.

Open source

Secondary source

Sector 1 City Hall: IT-system outage, contemporaneous report

HotNews · 2016-09-13

Open source

Secondary source

CERT-RO: investigation of ransomware incidents at four hospitals

AGERPRES · 2019-06-20

Open source

Secondary source

Oradea City Hall: document-system outage, contemporaneous report

TVR · 2021-07-03

Open source

Secondary source

Romanian Education Ministry: May 2023 public-page incident

Radio România Actualități · 2023-05-08

Open source

Secondary source

Chamber of Deputies: initial estimate of approximately 250 GB

AGERPRES · 2024-01-30

The report records the digitalisation minister’s initial statement of approximately 250 GB. A later statement attributed to DNSC gave an incompatible figure.

Open source

Secondary source

STS: the attacked system was neither administered nor secured by STS

AGERPRES · 2024-01-30

The report quotes STS clarifying that it did not administer or provide cybersecurity for the attacked system.

Open source

Secondary source

DNSC, as reported by AGERPRES: 316 files totalling approximately 300 MB

AGERPRES · 2024-02-17

AGERPRES attributed to DNSC a figure of 316 files, approximately 300 MB. No public technical report reconciling it with the initial 250 GB estimate was identified.

Open source

Secondary source

Chamber of Deputies: subsequent restrictions on access to services and platforms

AGERPRES · 2024-02-20

The report describes subsequent measures communicated by the Chamber of Deputies.

Open source

Secondary source

DNSC: final count of 26 hospitals in the Hipocrate incident

AGERPRES · 2025-07-24

Open source

Secondary source

DNSC 2024 report, public summary

AGERPRES · 2025-08-27

Summary of DNSC’s annual report. Figures are attributed to the report, not independently verified.

Open source

Secondary source

Iași County Council: Facebook-page compromise, reported by Radio România

Radio România · 2025-10-05

Open source

Secondary source

Orăștie City Hall: October 2025 ransomware incident, local reporting

Cotidianul Hunedorean · 2025-10-15

Open source

Secondary source

Digi Economic — Brașov Fiscal Directorate website temporarily disconnected

Digi Economic · 2026-07-20

The report reproduces the City Hall statement and, at the verification date, adds no independent technical detail.

Open source