Lithuania’s 600,000 Registry Files Stolen

Europe’s foundational registries are leaking millions of records through unguarded digital back doors.
Cumadóireacht íomhá · tobriefAcross Europe, the proof that you own a home, run a company, or hold a mortgage sits inside a state database. These registries are the quiet legal machinery behind ownership. In 2026, at least five EU member states have suffered major breaches of those systems, exposing millions of records. The infrastructure that carries some of the most basic facts of economic life is less protected than most citizens would assume.
Stealing the Cleaning Company's Key
On May 22, Lithuania's Prosecutor General confirmed that attackers had illegally copied more than 600,000 records from the country's property and corporate registries. The material included real-estate ownership details and legal entity filings. The head of the Registers Centre resigned the same day.
The troubling part is how the attackers got in. Lithuanian investigators found that unauthorised logins came from abroad, routed through systems run by other state institutions. They did not simply batter the registry's front door. They compromised a trusted neighbouring system and used its credentials to enter. It was the digital equivalent of getting into a building by stealing a key from the cleaning company.
The stolen data has obvious criminal value. Property records matched with owner names can be used for identity fraud, false mortgage applications, or shell companies created for money laundering.
Five Countries, Same Weakness
Lithuania is the latest case, but the weakness is wider than one country.
In Malta, a Berlin-based security researcher downloaded 1.3 million corporate documents from the Business Registry through a misconfigured API, the digital interface that lets software query a database. No hacking was needed. The API charged €0.01 per document and placed no limit on access.
In Bulgaria, the Justice Minister demanded the dismissal of the Registry Agency's director after an inspection found 60% of positions vacant and no information security officer on staff.
In Italy, Naples prosecutors dismantled a network in which two police officers made roughly 730,000 unauthorised queries to state databases over two years. Personal data was sold at fixed prices: €25 for an Interior Ministry lookup and €6-11 for tax records. The system logged every access, but never flagged the pattern. Eighty-five people were investigated. France has also faced a wave of breaches hitting public administration systems, including incidents affecting more than 1.2 million bank accounts, according to To Brief's earlier reporting.
The common failure is not that these systems recorded nothing. They recorded who logged in. What they did not do was notice when ordinary access turned abnormal.
The Gap Between Law and Locks
The EU's NIS2 directive, in force since October 2024, classifies public administration as one of the sectors requiring the highest cybersecurity standards. National registries qualify as "essential entities", which means mandatory risk assessments and incident reporting within 24 hours.
The law is ahead of the locks. In Germany, which transposed the directive only in December 2025, roughly 38% of affected organisations had registered with the federal cybersecurity authority by the March 2026 deadline, according to To Brief's earlier reporting. It is still unclear whether all German states have even registered their property registries.
Lithuania had already transposed NIS2 when its registries were breached. The directive requires access controls, but does not explicitly require automated anomaly detection. In plain terms, if someone who usually runs ten queries a day suddenly runs ten thousand, the system should raise an alarm. These registries did not have that capability.
Estonia's X-Road architecture shows a partial answer. Every query between government systems gets a tamper-proof digital signature, creating detailed records of who accessed what and when. That makes mass data extraction much harder to hide. Even X-Road, though, cannot fully stop an insider abusing legitimate credentials.
These registries record who owns a house, who directs a company, and who holds a mortgage. They do not carry the immediate drama of a ransomware attack on a hospital. But they are the legal plumbing of European economies, and that plumbing is leaking across the continent. Europe's regulatory architecture has not yet caught up with the scale of the threat.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 5/23/2026, 3:29:24 AM
- Pipeline run:
- eu_pipeline_20260523_015006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication