Find notable cyber news and cases, enriched with sources, timelines, and signals.

Romanian Waters (Administrația Națională Apele Române) hit by ransomware attack

Incident
First reported
Last updated
Happening score
H score 19
1 unique sources, 1 articles

Summary

Hide ▲

Romanian Waters (Administrația Națională Apele Române) was hit by a ransomware attack that disrupted about 1,000 systems across 10 of 11 regional offices, while OT water controls stayed unaffected. Attackers reportedly used Windows BitLocker to lock files and left a ransom note demanding contact within 7 days. Romanian agencies are investigating and working to contain the impact. The incident affected core IT services including GIS, databases, email, web services, and domain name servers.

Related Happenings

Gentlemen ransomware affiliate campaign expanding toolkit and infrastructure

Campaign
H score53 First: 20.04.2026 23:02 Last: 20.04.2026 23:02 Sources 1

About this happening: The Gentlemen ransomware campaign now spans a December 29, 2025 attack on Oltenia Energy Complex and later analysis of its evolving infrastructure. The company said so...

Aleksey Olegovich Volkov sentenced in Yanluowang ransomware case

Law Enforcement
H score35 First: 24.03.2026 15:06 Last: 24.03.2026 15:06 Sources 1

About this happening: The Justice Department said Aleksey Olegovich Volkov was sentenced to 81 months in prison for serving as an initial access broker in Yanluowang ransomware atta...

INC ransomware healthcare targeting campaign across Oceania

Campaign
H score42 First: 12.03.2026 00:00 Last: 12.03.2026 00:00 Sources 1

About this happening: The INC ransomware operation has expanded its targeting of healthcare organizations across Oceania, increasing the risk of service disruption and data theft. T...

Oltenia Energy Complex (Complexul Energetic Oltenia) hit by ransomware attack

Incident
H score21 First: 29.12.2025 16:26 Last: 29.12.2025 16:26 Sources 1

About this happening: A ransomware attack hit Oltenia Energy Complex and encrypted files while taking key business systems offline, disrupting operations during the holiday period. ERP, d...

Nefilim ransomware extortion campaign targeting high-revenue businesses

Campaign
H score79 First: 22.12.2025 11:46 Last: 22.12.2025 11:46 Sources 1

About this happening: The Nefilim ransomware campaign used an affiliate model that traded code access for 20% of ransom payments and focused on high-revenue businesses rather than indiscrim...

Timeline

  1. 22.12.2025 17:25 2 articles · 6mo ago

    Romanian Waters ransomware attack disclosed

    Initial Disclosure

    Romanian Waters (Administrația Națională Apele Române) was hit by a ransomware attack over the weekend, disrupting approximately 1,000 computer systems across 10 of its 11 regional offices while OT systems controlling water infrastructure remained unaffected. Romanian security agencies, including the Romanian Intelligence Service's National Cyberint Center, were investigating and working to contain the impact after finding that attackers used Windows BitLocker to lock files and left a ransom note demanding contact within 7 days; the attack vector had not yet been identified.

    Show sources