Trusted Registry Logins Exposed 600,000 Records

The break is in account trust, not the registry software. Someone used credentials already issued to authorized institutions, so the access looked legitimate and opened sensitive property and identity records as if the user belonged there. Authorities say more than 600,000 records from Lithuania’s Real Estate and Legal Entities registers were accessed this way. The exposed data included names, birth dates, national IDs, addresses, cadastral information, and registry numbers, and investigators suspect a foreign actor. Officials have since blocked suspected accounts and forced credential updates, which shows the access path was trusted enough to work until after the fact.

Part of the PlainSec briefing for 2026-05-27

Sources