SYS::ONLINE
Wasteland.
Briefs1634
Issues21
SinceFeb 2026
LIVE
█ Ransomware ROMANIA-ANP-PENITE 2026-07-31

Romania's National Administration of Penitentiaries: Babuk Suspected Ransomware Attack

"Romania's National Administration of Penitentiaries (Administrația Națională a Penitenciarelor, ANP) was hit by ransomware on 29 July 2026, encrypting workstations and servers across the agency and forcing the physical…"

Romania's National Administration of Penitentiaries (Administrația Națională a Penitenciarelor, ANP) was hit by ransomware on 29 July 2026, encrypting workstations and servers across the agency and forcing the physical disconnection of equipment at every prison unit in the country. The National Cyber Security Directorate (DNSC) confirmed it was notified at 08:00 local time through the national 1911 emergency line and dispatched specialists on site the same morning. DNSC head Dan Câmpean told Romanian media that the preliminary analysis points to the Babuk ransomware group, while stressing that attribution is not confirmed. ANP has said it will file a criminal complaint with DIICOT, Romania's organised crime and terrorism directorate. Inmate telephony, the visit booking portal, inter-site VPN links and the agency website all went dark; prisoner transfers between units were suspended and court appearances shifted to videoconference.

What Happened

The core facts are consistent across ANP's own statement, the DNSC's public post, and Romanian press coverage: a ransomware attack struck "several workstations and servers belonging to ANP" on Wednesday 29 July. ANP's IT team contacted DNSC, which intervened to limit the blast radius by physically isolating all equipment rather than relying on network segmentation alone.

A more granular timeline was released by ANP on Thursday 30 July and reported by Realitatea de Gorj. According to that reconstruction, the intrusion began late on the night of 28 July, close to midnight, and continued into the following morning. Mass encryption started around 07:00. The first alert about system unavailability arrived at 07:15, and the first confirmed encryption events were reported at 07:35. By 07:50 ANP had activated its full inter-site isolation protocol, and by 10:00 the physical disconnection of all equipment across subordinate units was complete. The operation took several hours because of the sheer number of prisons under ANP control. Note the seam between accounts: ANP describes contacting DNSC "immediately," while DNSC dates its own notification to 08:00, roughly 45 minutes after the first alert and 25 minutes after the first confirmed encryption. That is a plausible internal triage gap rather than a contradiction, but it is worth reading as a real detection-to-escalation interval.

Services taken offline as a precaution, per ANP and reproduced consistently by HotNews, PressHub and NewsRecorder: IMS Web (the inmate records application), Infokiosk, the telephony system for detainees, the visit scheduling portal, VPN connections between locations, and www.anp.gov.ro. Câmpean framed the shutdowns as deliberate containment, saying a number of ANP servers were impacted and that "out of an excess of caution" part of the institution's services and equipment were taken offline to limit propagation.

The operational fallout landed directly on detainees. ANP established interim workarounds: each inmate may place one call per day of up to five minutes, restricted to the last numbers dialled before the attack; visit and online communication bookings moved to phone or in-person counter service; purchases shifted to in-prison shops or staff-mediated ordering. Court appearances scheduled for 29 July were honoured, with subsequent hearings moved to videoconference on prior notice to the courts. Inter-unit transfers were halted, with exceptional cases handled individually.

What Was Taken

No source in this set reports data theft, and no leak-site listing or extortion note has been made public as of this writing. Treat this as an encryption-impact incident until proven otherwise, but do not treat "no exfiltration reported" as "no exfiltration." Modern Babuk-lineage operations routinely stage data before detonation, and ANP itself has said the initial access path is still unknown, which means the dwell period and any staging activity within it remain uncharacterised.

On the damage side, ANP's preliminary verification is comparatively good news. Databases and backups for the important applications, including IMSWeb, the inmate records system, were reported intact. Other databases were partially affected, and specialists are assessing recovery options. ANP stated that restoration will only begin after verification is complete and any vulnerabilities have been fully eliminated, and that essential prison-system activities continued within normal parameters.

The sensitivity of what sits inside those systems is the point. A prison administration holds custody records, movement and transfer schedules, visitor identities and booking history, phone contact lists, staff rosters, and medical and disciplinary files. Even without a confirmed leak, an adversary with access to transfer scheduling and inmate location data holds information with direct physical-safety value.

Why It Matters

This is a critical-infrastructure incident dressed as an IT outage. When the visit portal and inmate telephony go down, the state's legal obligations to people in its custody do not pause. ANP's five-minute-call workaround and counter-based visit booking are a functioning contingency, but they are manual substitutes running at a fraction of normal throughput, and the suspension of prisoner transfers has knock-on effects across the courts.

The reported preservation of IMSWeb databases and backups is the single most important defensive detail here. It suggests either that backups were segmented away from the encrypted estate or that containment outran the encryptor. The four-hour window from first alert at 07:15 to full physical disconnection at 10:00 across a national estate is a credible containment result, achieved by pulling cables rather than trusting the network.

Câmpean was explicit that this attack has no correlation with the earlier incident at Romania's National Cadastre Agency, and that while Babuk members are Russian-speaking they cannot be explicitly associated with a state actor. He also noted that tens of thousands of cyber attacks are recorded daily in Romania, of which only a small fraction succeed. Analysts should resist stitching these Romanian public-sector incidents into a single campaign narrative on current evidence.

Attribution caution is warranted for a second reason. Babuk's source code and builder leaked publicly in 2021 and have been reused by numerous unrelated crews since. A "Babuk" identification from artefacts or ransom-note formatting may indicate a derivative rather than the original group. Câmpean's own phrasing reflects this: the name is "the one being circulated," but it cannot be firmly confirmed.

The Attack Technique

Initial access is unknown. ANP said plainly on 30 July that the route the attackers used into the network has not been established, and that technical teams and cyber security authorities are continuing verification while working to limit effects and rebuild systems. Sourcing on the technique is thin and no source in this set names an exploited CVE, a phishing lure, or a compromised credential.

What the timeline does support is a compressed operation: intrusion activity beginning near midnight on 28 July, encryption launched around 07:00 the next morning, hitting both workstations and servers, with propagation sufficient across inter-site links that ANP judged full physical isolation necessary rather than selective quarantine. The existence of VPN connections between locations, listed among the services shut down, is a natural lateral-movement path in an estate of this shape, though no source confirms it was the vector. Ransomware groups in this lineage typically arrive through internet-facing remote access, unpatched edge appliances, or valid accounts, then escalate to a domain-wide deployment overnight.

What Organizations Should Do

  1. Rehearse physical isolation, not just logical segmentation. ANP's containment worked because staff could disconnect equipment at every subordinate unit, and it still took until 10:00 to finish. Time that drill for your own estate and know who has hands on cables at each site out of hours.

  2. Harden and monitor site-to-site VPN and remote access. Enforce phishing-resistant MFA on every remote entry point, patch edge appliances on an emergency cadence, and alert on anomalous administrative authentication between sites, particularly during overnight hours when this attack ran.

  3. Verify that backups survive a domain-wide compromise. ANP's intact IMSWeb backups are why this is a recoverable incident. Keep immutable or offline copies outside the production trust boundary and test restoration against the assumption that domain admin is in adversary hands.

  4. Instrument for mass-encryption behaviour, not signatures. The gap from first encryption at roughly 07:00 to first confirmed report at 07:35 is where automated detection pays for itself. Canary files, honeypot shares, and volume-based alerting on file rename and write operations shorten that window materially.

  5. Restore only after root cause is closed. ANP is explicitly holding restoration until verification finishes and vulnerabilities are eliminated. That sequencing is correct and frequently skipped under operational pressure; rebuilding into an unremediated network invites a second detonation.

  6. Pre-build manual continuity procedures for citizen-facing obligations. ANP had answers for detainee phone calls, visit bookings, purchases and court appearances within hours. Public-sector operators should have equivalent degraded-mode playbooks documented, delegated and rehearsed before the outage, not drafted during it.

  7. Treat unattributed ransomware as potential double extortion. With no leak-site posting yet and no confirmed exfiltration, monitor extortion infrastructure, preserve forensic evidence for the DIICOT investigation, and prepare breach notification on the assumption data left the building.

Sources: ANP Ransomware Attack Response Statement | ransomware-attack-on-the-penitentiary-administration-the-babuk-grou... | Administrația Națională a Penitenciarelor, vizată de un atac cibern... | În data de 29 iulie 2026, la ora 08.00, Directoratul Național de Se... | Atac cibernetic la ANP: Detalii despre ransomware | Administrația Națională a Penitenciarelor, vizată de un atac cibern... | BREAKING NEWS! Atac cibernetic asupra Penitenciarelor din România.... | Realitatea de Gorj ANP dezvăluie cronologia atacului informatic. M...