On December 20, 2025, the Romanian National Water Administration , known as Apele Române , revealed that it had suffered a widespread ransomware attack , which affected a significant part of its information systems. This is an incident that brings to the fore the risks that critical infrastructures face from increasingly aggressive cyber threats.

According to initial estimates, around 1,000 IT systems were breached at central and regional level, affecting 10 of the 11 river basin administrations under the organization.
Which systems were affected?
The attack was not limited to individual workstations. Instead, the perpetrators managed to gain access to critical digital infrastructure, including:
- Geographical Information System (GIS) application servers
- Databases
- Windows servers and workstations
- Email and web servers
- DNS systems
The extent of the breach indicates an organized and well-planned attack, aimed at paralyzing the organization's administrative and support functions .
See also: Baker University: Data breach affects 53,000 people
Abuse of BitLocker as an attack weapon
Of particular interest is the fact that the attackers used BitLocker, the built-in and perfectly legal Windows encryption mechanism, to lock files on the infected systems. This technique makes it more difficult to immediately detect the attack, as it does not exploit external malware, but a native function of the operating system.

Business impact and ransom demands
The affected regional administrations include facilities in areas such as Oradea, Cluj, Iasi, Siret and Buzău. The perpetrators left a ransom note, demanding contact within seven days.
However, Romania's National Directorate for Cybersecurity (DNSC) follows a strict policy of not negotiating with criminal groups, emphasizing that paying ransoms encourages further criminal activity and does not guarantee data recovery.
Immediate mobilization of the authorities
The incident is being investigated by technical teams from the DNSC, the National Cybersecurity Center (CNC) under the Romanian Intelligence Service, and other competent authorities. In parallel, the gradual restoration of the affected IT systems is underway.
Authorities are prioritizing maintaining data security and integrity, while a full return to normal operation is expected to occur gradually.
Critical infrastructure withstood
Despite the scope of the cyberattack, one particularly positive aspect is that the operational technology (OT) systems, which control dams, hydropower projects and water flows, remained unaffected. This allowed water resource management to continue without interruption.
See also: Nissan: Customer data breach due to Red Hat attack
Operations were coordinated via telephone and radio communications, while technical personnel continued to supervise on-site facilities. Forecasting and flood protection activities were not disrupted.

A timeless gap in the protection of water infrastructure
The research revealed that Romania’s water infrastructures were not previously fully integrated into the national critical infrastructure cyber protection system. The authorities have already initiated procedures to integrate these systems into the central protection framework managed by the CNC.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A warning message for Europe
The Apele Române incident is yet another example of the increasing targeting of public services by ransomware groups. Water and energy are now considered high-value targets, as their disruption can have serious social and political consequences.
See also: DDoS attack targeted France's National Postal Service
As the investigation continues, Romanian authorities have made it clear that the main priority remains the full restoration of information systems, without compromising the security and functionality of the country's water management. The incident serves as a resounding reminder of the need to strengthen cyber resilience across Europe.
