Romanian Waters confirms cyberattack critical water operations unaffected
pThe ideals of Aaron Swartz in an age of controlppSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 79ppSecurity Affairs newsletter Round 558 by Pierluigi Paganini INTERNATIONAL EDITIONppA massive breach exposed data of 175M Instagram usersppNorth Korealinked APT Kimsuky behind quishing attacks FBI warnsppIllinois Department of Human Services IDHS suffered a data breach that impacted 700K individualsppTrend Micro fixed a remote code execution in Apex CentralppIran cuts Internet nationwide amid deadly protest crackdownppChinalinked UAT7290 spies on telco in South Asia and Europe using modular malwareppChinesespeaking hackers exploited ESXi zerodays long before disclosureppAstaroth banking Trojan spreads in Brazil via WhatsApp wormppUS CISA adds HPE OneView and Microsoft Office PowerPoint flaws to its Known Exploited Vulnerabilities catalogppChinalinked groups intensify attacks on Taiwans critical infrastructure NSB warnsppNi8mare flaw gives unauthenticated control of n8n instancesppMisconfigured email routing enables internalspoofed phishingppVeeam resolves CVSS 90 RCE flaw and other security issuesppHackers actively exploit critical RCE flaw in legacy DLink DSL routersppFake Bookingcom lures and BSoD scams spread DCRat in European hospitality sectorppCERTCC warns of critical unfixed vulnerability in TOTOLINK EX200ppGoogle fixes critical Dolby Decoder bug in Android January updateppRomanian Waters Administrația Națională Apele Române the countrys water management authority suffered a ransomware attack over the weekend ppAccording to the National Cyber Security Directorate DNSC the incident affected around 1000 computer systems across the central organization and 10 of its 11 regional offices The attack disrupted IT assets including GIS servers databases email and web services Windows workstations and domain name servers ppAuthorities stressed that operational technology OT systems managing water infrastructure were not impacted and water operations continue to function normallyppThe National Directorate of Cyber Security DNSC was notified on December 20 2025 of a ransomware cyber attack on several workstations and servers belonging to the National Romanian Waters Administration and a number of 10 out of 11 water basin administrations in the country including Oradea Cluj Iași Siret Buzău reads the press release published by DNSC Due to this cyber incident approximately 1000 ITC systems were compromised including Geographical Information System GIS application servers database servers Windows workstations Windows Server servers emailweb servers and Domain Name Servers DNSppTechnical teams from the DNSC Romanian Waters the SRIs National Cyberint Center affected entities and other authorities are actively investigating the incident and working to contain its impact DNSC states that the Romanian Waters infrastructure is not yet connected to the national cyber protection system operated by CNC Authorities have started the process to integrate it into CNCs security platforms which use advanced technologies to protect critical public and private IT and communications infrastructure from cyber threatsppGovernment experts who are investigating the incident confirmed that threat actors used Windows BitLocker to encrypt systems and issued a ransom note demanding contact within seven days However at this time the attack vector has not yet been identifiedppDNSC reiterated its strict advice not to contact or negotiate with ransomware actors to avoid encouraging and funding cybercrimeppWe recommend that the ITC teams of the Romanian Waters National Administration or the basin administrations not be contacted so that they can focus on restoring IT services concludes the reportppIn early December CISA alongside the FBI NSA Europols EC3 and other global partners warned that proRussia hacktivist groups such as ZPentest Sector16 NoName and the Cyber Army of Russia Reborn are actively targeting critical infrastructure organizations worldwideppIn early December US CISA together with the FBI NSA European Cybercrime Centre EC3 and various other cybersecurity and law enforcement agencies worldwide warned that proRussia hacktivist groups including ZPentest Sector16 NoName and CARR Cyber Army of Russia Reborn are targeting critical infrastructure organizations worldwideppFollow me on Twitter securityaffairs and Facebook and MastodonppPierluigi PaganinippSecurityAffairs hacking Romanian WatersppppSecurity January 11 2026ppBreaking News January 11 2026ppBreaking News January 11 2026ppData Breach January 10 2026ppIntelligence January 10 2026ppTo contact me write an email to
Pierluigi Paganini
email protected
pp
Copyrightsecurityaffairs 2024 p
Pierluigi Paganini
email protected
pp
Copyrightsecurityaffairs 2024 p