Technology

Ransomware attack on Romanian water agency hits over a thousand systems

2025-12-23 13:05
513 views
Ransomware attack on Romanian water agency hits over a thousand systems

An unknown threat actor wreaked some serious havoc but operations are continuing unabated.

  1. Pro
  2. Security
Ransomware attack on Romanian water agency hits over a thousand systems News By Sead Fadilpašić published 23 December 2025

An unknown threat actor wreaked some serious havoc across Romania

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website (Image credit: sarayut Thaneerat/ via Getty Images) Share Share by:
  • Copy link
  • Facebook
  • X
  • Whatsapp
  • Reddit
  • Pinterest
  • Flipboard
  • Threads
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google
  • Romania’s ANAR hit by ransomware, affecting around 1,000 systems across river basin organizations
  • Attackers used Windows BitLocker; ransom note left, negotiations discouraged by DNSC
  • Hydrotechnical operations continue; website offline, updates shared via DNSC’s X account

Administrația Națională Apele Române (ANAR), Romania’s national public authority responsible for managing the country’s water resources, has confirmed suffering a rather disruptive ransomware attack.

As per the announcement, on December 20, an unidentified threat actor struck its geographical information system applications servers, database servers, Windows workstations, Windows Servers, email and web servers, and domain name servers. The attack then trickled down to almost all of the country’s river basin management organizations, further complicating things.

In total, around 1,000 systems are currently affected, The Register claims. It still provides its service to the Romanians, it was said, with hydrotechnical operations continuing as normal, thanks to on-site staff.

You may like
  • The importance of Layer 1 infrastructure in AV over IP networks Experts warn UK's basic infrastructure at risk after hackers target drinking water suppliers
  • Sweden power grid confirms cyberattack, ransomware suspected
  • Hands on a laptop with overlaid logos representing network security Pro-Russian hackers tricked into attacking decoy target

BitLocker used

ANAR is a state-owned public institution operating under Romania’s Ministry of Environment. It manages surface and groundwater resources, oversees dams, reservoirs, and flood defense infrastructure, and monitors water quality nationwide. The agency is also pivotal in flood prevention, drought mitigation, and compliance with EU water directives.

At press time, the organization’s website remains offline as well, so official news is being distributed via alternative channels, including the X account of the Romanian National Cyber Security Directorate (DNSC).

Romanian Waters did not say who the threat actors are, or how they managed to cause such a large incident. It did say that this was a ransomware attack, since many files were encrypted, and a ransom note was left. The company was apparently given a week to begin negotiations.

DNSC claims the threat actors used Windows BitLocker to encrypt files, hinting that this was not the doing of a prolific hacking group.

Are you a pro? Subscribe to our newsletterContact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

"We reiterate that DNSC's strict policy and recommendation towards all victims of ransomware attacks is to neither contact nor negotiate with cyberattackers, to avoid encouraging or financing the cybercrime phenomenon," the agency stressed.

"We recommend avoiding contacting the IT&C teams of the National Administration 'Romanian Waters' or ones of the river basin administrations, so they can focus on restoring the impacted IT services.”

Best antivirus software headerThe best antivirus for all budgetsOur top picks, based on real-world testing and comparisons

➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Sead FadilpašićSocial Links Navigation

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Show More Comments

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Logout Read more The importance of Layer 1 infrastructure in AV over IP networks Experts warn UK's basic infrastructure at risk after hackers target drinking water suppliers    Sweden power grid confirms cyberattack, ransomware suspected    Hands on a laptop with overlaid logos representing network security Pro-Russian hackers tricked into attacking decoy target    Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration Top infostealer disrupted after criminals lose server access    A person holding a phone looking at a text with warning signs Emergency alert systems across US disrupted following OnSolve CodeRED cyberattack    Asahi stops pouring after cyberattack stops production    Latest in Security Nissan Titan Nissan says Red Hat breach affected thousands of customers    Christmas scams Phishing emails and fake adverts flood inboxes this Christmas - and they’re getting harder to detect than ever    NordProtect logo NordProtect adds fraud monitoring tool to help protect users from scams    Ransomware University of Phoenix data breach may have hit over 3.5 million victims - here's what we know    Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration. HPE tells customers to patch OneView immediately as top-level security flaw spotted    Security padlock and circuit board to protect data Motherboards from Gigabyte, MSI, ASUS, ASRock at risk from new UEFI flaw attack - here's what we know    Latest in News Deadpool addresses the camera Marvel Rivals studio teases a big year ahead for the game — 'We're not going to slow down'    Corsair lighting enhancement kit Vengeance DDR5 shown in motherboard DDR5 RAM kit from Corsair was reportedly swapped for dummy RGB modules    Dyson Spot+Scrub Ai robot vacuum in tester's house Dyson Spot+Scrub Ai robot vacuum first impressions: redemption?    Surfshark Surfshark expands dedicated IP to Linux in its latest desktop update    Clair Obscur: Expedition 33 ‘It’s good to have limitations’: Clair Obscur: Expedition 33's creative director says Sandfall Interactive's next game won’t on a bigger scale despite huge success    The official logo for Marvel's Avengers: Doomsday movie written in gray and green text on a black background Avengers: Doomsday's first trailer is now online officially    LATEST ARTICLES