- On December 20, 2025, Romania’s national water management authority, Apele Române, was hit by a major ransomware attack that compromised its IT systems.
- Around 1,000 computer systems were affected across the central agency and 10 out of 11 regional water basin administrations, including offices in Oradea, Cluj, Iași, Siret, and Buzău.
Systems Impacted
The attack disrupted large parts of the organization’s IT infrastructure, including:
- Geographic Information System (GIS) servers
- Database servers
- Windows workstations and servers
- Email and web servers
- Domain Name Servers (DNS)
However, operational technology (OT) systems that directly control water infrastructure (like dams and hydrotechnical assets) were not affected, meaning physical water operations continued normally.
Ransomware Technique Used
Investigators believe the attackers abused Microsoft’s built-in BitLocker encryption tool to lock files rather than deploying external ransomware binaries — a tactic known as “living off the land.”
A ransom note was left demanding contact within seven days, but authorities discouraged negotiation with the attackers.
Response and Recovery
- Romania’s National Cyber Security Directorate (DNSC) has confirmed the incident and is coordinating remediation and investigation efforts.
- The agency’s website remains offline, with updates shared through alternative channels.
- Staff are using telephone and radio communications to manage essential operations while IT systems are restored.
Broader Context and Implications
- This attack highlights the growing ransomware threat to critical public infrastructure, especially utilities like water management agencies.
- The incident has accelerated plans to integrate water infrastructure systems into Romania’s national cyber defense frameworks to better protect against future incidents.
Key Takeaways
- The incident was IT-system focused, not directly affecting water delivery or safety.
- No specific threat group has publicly claimed responsibility yet, and the method of initial access remains under investigation.
- Use of trusted system tools like BitLocker in ransomware attacks demonstrates how adversaries increasingly bypass traditional malware detection.
