Skip to main content
TECH_SCIENCE08 / 08 · story of the day3 min · 636 words · 146 sources

Lithuania Loses 600,000 Registry Records

Written by AIto brief AI · 23 ta’ Mejju 2026, 03:50
How it was written

Europe’s foundational registries are leaking millions of records through unguarded digital back doors.

Image composition · tobrief
the text · 3 min read

Every property deed, company registration and mortgage record in Europe depends on a state database. These registries are the legal machinery behind ownership. In 2026, at least five EU member states have seen major breaches of these systems, exposing millions of records. The digital infrastructure that decides who owns what is weaker than most Europeans assume.

Stealing the Cleaning Company's Key

On 22 May, Lithuania's Prosecutor General confirmed that attackers had illegally copied more than 600,000 records from the country's property and corporate registries. The stolen data included real estate ownership details and legal entity filings. The head of the Registers Centre resigned the same day.

The method matters. Lithuanian investigators found that unauthorised logins came from abroad, routed through systems run by other state institutions. The attackers did not break through the registry's main entrance. They compromised a trusted neighbouring system and used its credentials to get in. It is the digital equivalent of entering a building with a key stolen from the cleaning company.

That data has immediate criminal value. Property records matched with owner names can support identity fraud, false mortgage applications, or shell companies created for money laundering. For Malta, where corporate services and financial regulation are never abstract questions, the point is familiar: a registry is not just an archive. It is part of the country's economic plumbing.

Five Countries, Same Weakness

Lithuania is the latest case, but the weakness is wider.

In Malta, a Berlin-based security researcher downloaded 1.3 million corporate documents from the Business Registry through a misconfigured API, the digital interface that lets software query a database. No hacking was needed. The API charged €0.01 per document and placed no effective limit on access.

Bulgaria's Justice Minister demanded the dismissal of the Registry Agency's director after an inspection found 60% of positions vacant and no information security officer on staff.

In Italy, Naples prosecutors dismantled a network in which two police officers made roughly 730,000 unauthorised queries to state databases over two years. They sold personal data at fixed prices: €25 for an Interior Ministry lookup, €6-11 for tax records. The system recorded every access but never treated the pattern as suspicious. Eighty-five people were investigated.

France has also faced a wave of breaches hitting public administration systems, including incidents affecting more than 1.2 million bank accounts, according to To Brief's earlier reporting.

The common failure is access monitoring. The systems knew who logged in. They did not notice when normal use became mass extraction.

The Gap Between Law and Locks

The EU's NIS2 directive, in force since October 2024, puts public administration among the sectors requiring the highest cybersecurity standards. National registries qualify as "essential entities". That means mandatory risk assessments and incident reporting within 24 hours.

The law is ahead of the locks. In Germany, which transposed the directive only in December 2025, roughly 38% of affected organisations had registered with the federal cybersecurity authority by the March 2026 deadline, according to To Brief's earlier reporting. It remains unclear whether all German states have even registered their property registries.

Lithuania had already transposed NIS2 when its registries were breached. The directive requires access controls, but it does not explicitly demand automated anomaly detection. In plain terms: if someone who normally runs ten searches a day suddenly runs ten thousand, the system should raise an alarm. These registries did not have that capacity.

Estonia's X-Road architecture shows one way to narrow the gap. Every query between government systems gets a tamper-proof digital signature, creating detailed records of who accessed what and when. Mass extraction becomes harder to hide. Even that model cannot fully stop abuse by an insider using legitimate credentials.

These databases record who owns a house, who directs a company and who holds a mortgage. They do not carry the drama of a ransomware attack on a hospital. But they are the legal plumbing of European economies, and that plumbing is leaking across the continent. Europe's cybersecurity rules have not yet caught up with the scale of the risk.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
5/23/2026, 3:29:24 AM
Pipeline run:
eu_pipeline_20260523_015006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology