Skip to main content
TECH_SCIENCE08 / 08 · story of the day3 min · 603 words · 146 sources

Lithuania loses 600,000 property records

Written by AIto brief AI · 23 May 2026, 03:50
How it was written

Europe’s foundational registries are leaking millions of records through unguarded digital back doors.

Image composition · tobrief
the text · 3 min read

Every property deed, company registration, and mortgage record in Europe sits in a government database. These registries are the legal backbone of ownership. In 2026, at least five EU member states have suffered major breaches of exactly these systems, exposing millions of records. Europe's most foundational digital infrastructure is far less protected than its citizens assume.

Stealing the Cleaning Company's Key

On May 22, Lithuania's Prosecutor General confirmed that attackers had illegally copied more than 600,000 records from the country's property and corporate registries. The stolen data included real-estate ownership details and legal entity filings. The head of the Registers Centre resigned the same day.

The entry point is what makes this alarming. Lithuanian investigators found that unauthorized logins came from abroad, routed through systems run by other state institutions. Instead of hitting the registry's front door, the attackers compromised a trusted neighbouring system and used its credentials to walk right in. Think of it as breaking into a building not by picking the lock, but by stealing a key from the cleaning company.

The stolen data has direct criminal value. Property records paired with owner names can fuel identity fraud, fraudulent mortgage applications, or shell companies set up for money laundering.

Five Countries, Same Weakness

Lithuania is the freshest wound, but the pattern spans the continent.

In Malta, a Berlin-based security researcher downloaded 1.3 million corporate documents from the Business Registry through a misconfigured API (the digital interface that lets software query a database). No hacking was needed. The API simply charged €0.01 per document with no access limits.

Bulgaria's Justice Minister demanded the dismissal of the Registry Agency's director after an inspection found 60% of positions vacant and no information security officer on staff.

In Italy, Naples prosecutors dismantled a network in which two police officers made roughly 730,000 unauthorized queries to state databases over two years, selling personal data at fixed rates: €25 per Interior Ministry lookup, €6-11 for tax records. The system logged every access but never flagged the pattern. Eighty-five people were investigated. France, too, has faced a wave of breaches hitting public administration systems, including incidents affecting over 1.2 million bank accounts, according to To Brief's earlier reporting.

All five cases share a failure of access monitoring. The registries recorded who logged in but never noticed when those patterns turned abnormal.

The Gap Between Law and Locks

The EU's NIS2 directive, in force since October 2024, classifies public administration among sectors requiring the highest cybersecurity standards. National registries qualify as "essential entities," subject to mandatory risk assessments and incident reporting within 24 hours.

Implementation lags far behind the text. In Germany, which transposed the directive only in December 2025, roughly 38% of affected organizations had registered with the federal cybersecurity authority by the March 2026 deadline, according to To Brief's earlier reporting. Whether all German states have even registered their property registries remains unclear.

Lithuania had already transposed NIS2 when its registries were breached. The directive mandates access controls but does not explicitly require automated anomaly detection. In practical terms, if someone who normally runs ten queries a day suddenly runs ten thousand, the system should raise an alarm. None of these registries had that capability.

Estonia's X-Road architecture offers a partial counterexample. Every query between government systems gets a tamper-proof digital signature, creating detailed records of who accessed what and when. Mass data extraction becomes much harder to hide. Even X-Road, though, cannot fully prevent abuse by an insider with legitimate credentials.

These registries record who owns a house, who directs a company, who holds a mortgage. They lack the drama of a ransomware attack on a hospital. But they are the legal plumbing of European economies, and that plumbing is leaking across the continent. Europe's regulatory architecture has yet to catch up with the scale of the threat.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
5/23/2026, 3:29:24 AM
Pipeline run:
eu_pipeline_20260523_015006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology