Breaches · 111 days ago
The break is in account trust, not the registry software. Someone used credentials already issued to authorized institutions, so the access looked legitimate and opened sensitive property and identity records as if the user belonged there.
Authorities say more than 600,000 records from Lithuania’s Real Estate and Legal Entities registers were accessed this way. The exposed data included names, birth dates, national IDs, addresses, cadastral information, and registry numbers, and investigators suspect a foreign actor. Officials have since blocked suspected accounts and forced credential updates, which shows the access path was trusted enough to work until after the fact.
2 sources covering this story
The Record from Recorded Future
Lithuania investigates theft of 600,000 state registry records by foreign actor
The Lithuanian Prosecutor General’s Office said Friday that attackers gained unauthorized access to more than 600,000 records managed by the Centre of Registers, the state agency responsible for handling property and legal entity records.
Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries
Lithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers.
Part of the PlainSec briefing for 2026-05-27