Beyond the Fraud Triangle: What Romania’s Cadastre Attack Reveals About Cyber-Enabled Fraud

Alexandru Oană
Alexandru Oană

“For thousands of years men dreamed of pacts with demons. Only now are such things possible.”
– Neuromancer, William Gibson, 1984

1. Introduction

Lately, fraud and the fight against fraud have become hot topics in EU countries due to the recent adoption of the Directive (EU) 2026/1021 on combating corruption on 29 April 2026 and subsequent entry into force on 31 May 2026. While the main transposition deadline may seem far away on 1 June 2028, companies, boards, stakeholders and legal counsels started to take notice, prompted by the turnover-based fine architecture, and to take fraud prevention and detection more seriously.

To predict the conditions that lead to a high risk of fraud, anti-fraud professionals and researchers frequently rely on a concept called the “fraud triangle”. Drawing on criminological research Donald Cressey coined the term to model conditions that lead to a higher risk of fraud. According to Cressey, the fraud triangle states that individuals are motivated to commit fraud when three elements come together: (i) some kind of perceived pressure, (ii) some perceived opportunity, and (iii) some way to rationalize the fraud as not being inconsistent with one’s values.

Today, the fraud triangle is widely used by anti-fraud professionals to explain conditions that could motivate individuals or companies to engage in fraud. The model can also be used to highlight economic or industry-wide conditions that can lead to a higher overall risk.

For more than seventy years, the Fraud Triangle has provided fraud examiners with a powerful framework for understanding why individuals commit fraud. Pressure, opportunity and rationalization remain central to occupational fraud investigations, financial statement fraud and corruption cases, which represent some of the main types of fraud targeted by Directive (EU) 2026/1021.

Cybercrime, however, sets itself apart and does not rely so much on the conditions of the Fraud Triangle. Many of today’s cyber fraudsters have no relationship at all with their victims, be it individuals, companies or state authorities. They operate externally, exploiting technical vulnerabilities rather than organizational roles: ransomware operators may have no fiduciary connection to a target organization, yet they can still inflict significant financial and operational harm.

Recognizing this evolution, DeAndre Redd recently proposed the Six-Dimension (Six-D) Scorecard[1], extending the classical (i) motivation, (ii) opportunity and (iii) rationalization with three technical dimensions:

Technical capability covers the tools and skills used to exploit systems, from basic phishing kits to sophisticated exploits. Importantly, the rise of “as-a-service” cybercrime models has lowered the barrier to entry, meaning advanced attacks no longer imply advanced actors.

Digital anonymity is the ability to obscure identity and location through proxy systems, encryption, jurisdictional complexity and cryptocurrencies, making detection and attribution significantly more difficult.

Viral amplification is the capacity for fraud to expand rapidly and automatically. Traditional fraud tends to grow linearly with effort, cyberfraud grows exponentially. A single intrusion can propagate across networks, supply chains or global systems in minutes, magnifying impact far beyond the initial act.

The framework is intended not as a predictive model but as an investigative triage tool for distinguishing between behavioral, hybrid and technically driven cyber-enabled offenses.

The July 2026 cyberattack against Romania’s National Agency for Cadastre and Land Registration (“ANCPI”) presents an ideal opportunity to evaluate the framework and to show that cybercrime can disrupt not just a limited number of individuals or companies but nationwide public services and crucial economic markets. The incident of 14 July 2026 disrupted the e-Terra cadastral platform, interrupted property transactions across Romania and required the reconstruction of significant portions of ANCPI’s IT infrastructure after attackers encrypted and deleted elements of its virtualization environment. Official statements confirmed a ransomware attack, investigated jointly by the National Directorate of Cybersecurity (“DNSC”), the Special Telecommunications Service (“STS”) and Cyberint Service of the Romanian Intelligence Service (“SRI”), with recovery involving rebuilt infrastructure and safeguards such as network segmentation, privileged multi-factor authentication and continuous monitoring.

2. Reconstructing the ANCPI Incident

The attack became publicly visible on 14 July 2026 when ANCPI announced that the e-Terra platform and several internal systems had become unavailable. What was initially described as a major technical incident was subsequently confirmed to be a ransomware attack after forensic investigations identified unauthorized access to ANCPI’s infrastructure. Attackers encrypted and deleted portions of the agency’s virtualization infrastructure, forcing the complete reconstruction of critical systems before services could safely resume.

Unlike many cyber incidents that affect only internal operations, the disruption immediately propagated throughout Romania’s real estate ecosystem. Notaries were unable to authenticate transactions, banks could not process mortgage registrations, surveyors lost access to cadastral records, lawyers were unable to obtain land registry extracts, and property transfers across the country were effectively suspended until services could be restored.

Subsequent reporting identified the threat actor operating under the alias “ByteToBreach”, who claimed responsibility for the intrusion and asserted that stolen data, source code and internal documentation were being offered for sale. The attacker also claimed to have exploited a known vulnerability dating from 2021. Romanian authorities have not publicly verified all of these assertions, and they continue to maintain that the integrity of the official cadastral databases was preserved despite the operational disruption.

From an investigative perspective, the distinction between confirmed facts and threat actor claims is significant. The Six-D framework evaluates the characteristics of the offense rather than the credibility of extortion narratives. Accordingly, only those technical characteristics supported by official communications or multiple independent sources should influence scoring.

3. Applying the Six-Dimension Scorecard to the ANCPI cyberattack

Following Redd’s methodology, by scoring each dimension on a 1–10 scale and calculating a weighted average, examiners can quickly assess whether a fraud scheme is primarily behavioral (traditional) or primarily technical (cyber-enabled). This distinction matters because it determines which investigative resources and controls are most appropriate.

The formula weighs behavioral and technical factors roughly equally: Risk score = (behavioral average x 0.5) + (technical average x 0.5). The score is a way to organize judgment, not a measurement. It estimates nothing about the likelihood that fraud has occurred or who is responsible. It summarizes how a known scheme is distributed across behavioral and technical dimensions so that investigative resources can be matched to it. The decimal precision of the formula shouldn’t be mistaken for diagnostic precision.

Applying the scorecard across a range of documented fraud cases, from small fraud cases to more complex ransomware and supply chain compromise, a midpoint of approximately 5.0 has proven to be a useful divider in practice. Scores above 5.0 have generally corresponded to schemes that required technical investigative capabilities, and scores below 5.0 have generally corresponded to schemes resolved through traditional examination. This 5.0 mark is a heuristic anchor for triage, not an empirically optimized cutoff, and it should be treated as a starting point for professional judgment rather than a decision rule. The real value of the scorecard lies not in the final number but in the structured analysis that produces it.

Dimension Score Justification
Pressure 3 Available evidence suggests a financially motivated criminal enterprise rather than extraordinary personal, organizational or geopolitical pressure. In Cressey’s original sense, pressure denotes a non-shareable personal or organizational strain, which is why an ordinary profit motive scores low here.
Opportunity 8 Attackers exploited unauthorized access within critical national infrastructure, apparently leveraging compromised credentials and known technical weaknesses.
Rationalization 3 The operation reflects the detached, profit-oriented mindset commonly observed in ransomware groups targeting organizations with whom they have no prior relationship.
Technical Capability 8 Successful compromise of nationally significant infrastructure, ransomware deployment, destructive actions against virtualization infrastructure and coordinated operational disruption indicate substantial technical competence, although there is no public evidence of zero-day exploitation or nation-state capability.
Digital Anonymity 9 Attribution remains limited to an online alias. Cross-border investigation, anonymized criminal infrastructure and extortion practices substantially impede traditional investigative methods.
Viral Amplification 7 Although no evidence currently suggests worm-like self-propagation, the compromise of a centralized national platform generated cascading disruption across multiple dependent professional sectors.

Risk Score Calculation

Behavioral Average

(3 + 8 + 3) / 3 = 4.67

Technical Average

(8 + 9 + 7) / 3 = 8.00

Overall Risk Score

(4.67 × 0.5) + (8.00 × 0.5) = 6.34

The resulting score places the incident comfortably above the heuristic threshold proposed by Redd for technically driven cyber-enabled offenses.

4. Interpretation

The ANCPI cyberattack is best understood as a predominantly technical cyber-enabled offense.

Unlike traditional occupational fraud, behavioral factors explain relatively little about either the occurrence or the severity of the incident. Pressure and rationalization remain comparatively weak because the perpetrators operated as an external criminal enterprise rather than trusted insiders abusing organizational authority.

Instead, the defining characteristics of the incident reside within the technical dimensions:

technical capability enabled attackers to compromise nationally significant infrastructure.
digital anonymity significantly complicated attribution and investigation.

Most importantly, technical actions generated nationwide operational disruption extending well beyond ANCPI itself.

Accordingly, the Six-D Scorecard correctly signals that investigators should prioritize digital forensics, incident response, threat intelligence and infrastructure recovery before traditional fraud examination techniques.

5. An Extension to the Six-D Framework: Operational Amplification

Applying the Six-D Scorecard to the ANCPI incident also reveals an aspect of cyber risk that deserves further consideration. Redd’s Viral Amplification dimension primarily emphasizes technical propagation, automation, malware or supply-chain compromise spreading an attack from system to system.

The ANCPI incident, however, demonstrates a different mechanism: the attack required no self-propagating malware to produce nationwide consequences. Amplification arose instead from the fact that thousands of independent professional actors depended upon a single centralized digital platform, so that the interruption of one institution immediately disrupted notaries, banks, lawyers, surveyors, courts, citizens and the broader real estate market.

This suggests that, for critical public infrastructure, operational dependency may constitute a distinct form of amplification. The consequences of the ANCPI attack spread not because malware replicated autonomously, but because institutional dependency transformed a localized compromise into a nationwide operational crisis.

6. Lessons for Fraud Examiners

Several practical lessons emerge from the ANCPI case. Most fundamentally, traditional behavioral analysis alone cannot adequately explain modern ransomware incidents affecting critical infrastructure.

Opportunity remains essential, but in cyber-enabled offenses it increasingly reflects technical exposure rather than failures of organizational trust. Dimension-level analysis, in turn, proves more valuable than the aggregate score, because it directly informs how investigative resources should be allocated.

Finally, the case demonstrates that fraud examiners increasingly depend on collaboration with digital forensic specialists, cybersecurity professionals and threat intelligence analysts. The future of fraud examination is therefore multidisciplinary rather than exclusively behavioral.

7. Conclusion

The Six-Dimension Scorecard extends the Fraud Triangle convincingly into the digital era. Applied to the ANCPI cyberattack, it classifies the incident as a predominantly technical cyber-enabled offense, one defined not by offender psychology but by technological capability, anonymity and systemic operational impact. More importantly, the case shows that for centralized public infrastructure, dependency itself becomes a force multiplier, a single successful intrusion can disrupt entire sectors without any self-propagating malware. As governments centralize essential digital services, this distinction will matter increasingly to fraud examiners, investigators and policymakers, and frameworks like the Six-D Scorecard will prove their worth through refinement against real-world cases such as this one.

The incident also lands squarely within the European Union’s reshaped cybersecurity framework. Directive (EU) 2022/2555 (NIS2), transposed in Romania by Government Emergency Ordinance no. 155/2024 and expanded by Law no. 124/2025, subjects essential entities, expressly including public administration, to risk-management measures, DNSC registration, audits, staged incident reporting and management-level accountability. Tellingly, the DNSC, which enforces NIS2, also led the ANCPI investigation. NIS2 addresses precisely the dimensions where the ANCPI score concentrated, security measures reduce technical opportunity, reporting duties blunt the cost of digital anonymity, and its concern with service continuity implicitly treats operational dependency as the risk multiplier this article describes. Together with Directive (EU) 2026/1021, the result is a regulatory convergence, the same incident may now engage both anti-fraud and cybersecurity compliance regimes, and fraud examiners should expect to work at their intersection.


[1] DeAndre Redd, DBA, CFE, The Six-Dimension Scorecard: A proposed framework for assessing cyberfraud risk, Fraud Magazine no. 4, July / August 2026, Vol. 41, available for Association of Certified Fraud Examiners (“ACFE”) members https://www.acfe.com/fraud-magazine/all-issues.


Alexandru Oană, Attorney at Law