Skip to content
Stop Ransomware

Resource Center · Interviews & analysis

Inside the Mind of ByteToBreach: Money, Faith and the ANCPI Cyberattack

Published 20 July 2026 · Updated 20 July 2026 · 8 min read

Following his public claim of responsibility for the cyberattack affecting Romania's National Agency for Cadastre and Land Registration (ANCPI), I contacted the threat actor known as ByteToBreach.

He agreed to answer questions about his motivations, personal principles, target selection, views on the cybersecurity industry and the incident involving ANCPI. His answers were often brief, but direct. He describes himself as financially motivated, politically unaffiliated and driven by curiosity and the desire to learn.

He also denies requesting a EUR 10 million ransom from ANCPI and claims that cadastral data was exfiltrated but not modified.

Editorial note

The interview was conducted through Telegram. Answers have been lightly edited for spelling, grammar and clarity without changing their meaning.

The identity of the individual behind the account has not been independently verified. Statements concerning ANCPI are the actor's own claims and must not be treated as confirmed forensic findings.

Operational details that could facilitate additional attacks have not been included. Stop Ransomware does not link directly to illicit marketplaces or publish credentials, active endpoints or exploitation instructions.

Curiosity, learning and money

What first sparked your interest in hacking and cybersecurity? Was there a particular event, frustration or curiosity that pushed you towards it?

Curiosity.

Was there a specific incident in your life or in the news that strengthened your interest in this direction?

Nothing in particular.

Hackers frequently mention financial gain, ideology, revenge, technical challenges or a sense of justice. Which of these motivations resonate most with you?

My main motivation is money.

How important is recognition within the hacking community compared with financial outcomes?

Recognition is only important to me while attending DEF CON. Otherwise, I keep my identity private.

Despite identifying money as his primary motivation, ByteToBreach later explained that the learning experience itself remains an important part of his activity.

Which previous operation gave you the strongest sense of purpose or satisfaction?

Most operations give me a strong sense of satisfaction because of the learning experience. Money is a strong driver, but I am also very content with simply learning.

Attacking versus defending

How does the feeling of outsmarting large, well-funded organizations influence your motivation?

I could not say, because I have never outsmarted anyone. Attacking is much easier than defending a network with thousands of computers and an underfunded team.

His answer rejects the common image of the attacker as a technical mastermind defeating a perfectly secured organization. Instead, he points to the basic asymmetry between attackers and defenders: an attacker needs to identify one viable path, while a defensive team must protect a large and constantly changing environment.

What frustrates you most about the state of cybersecurity in government institutions?

Lack of funding.

When discussing the ANCPI incident, he returned to the same point and defended the people responsible for protecting large environments.

“Protecting a network, especially from the inside, is not an easy task. People should not be so hard on IT teams that work hard and overtime to keep everything under control. It does not excuse anything, but at least it helps people understand the issues better.”
ByteToBreach

Politics, faith and personal principles

How would you describe your political beliefs? Have they influenced your actions or target selection?

No politics.

Do you have personal values or principles that guide your decisions, both online and offline?

Christianity. The desire to learn.

At the end of the interview, when asked what message he would send to policymakers, cybersecurity professionals and ordinary internet users, his response was religious rather than technical:

“Stay faithful to Jesus Christ, our one true Savior and Lord.”
ByteToBreach

He did not address the apparent contradiction between his declared religious beliefs and his admission that he engages in financially motivated cybercrime.

How targets are selected

Why do you choose certain targets over others?

I decide on a whim.

The answer suggests that at least some of his activity is opportunistic rather than driven by a defined political, ideological or strategic objective.

Regarding ANCPI, he said the operation had a single motivation:

“It was financially motivated, nothing more.”
ByteToBreach

He also stated that he documents intrusions publicly because organizations may otherwise deny that a compromise occurred.

“I developed the habit of documenting my steps to avoid denials from companies.”
ByteToBreach

A line he says he will not cross

Is there anything you regret or any line you have deliberately chosen not to cross?

Hospitals, because of how dangerous it can be. During attacks involving healthcare systems in Brazil, I blacklisted entire subnets to avoid accidentally communicating with patient systems. I would rather not do it again.

This claim has not been independently verified. Avoiding hospitals does not remove the potential harm caused by attacks against other institutions, organizations or individuals. It does, however, indicate that he draws a distinction between targets based on the immediate risk to human life.

Governments and the cybersecurity industry

Do governments and law-enforcement agencies understand the current cyber-threat landscape, or are they constantly one step behind?

Yes, they understand it. Most ethical hackers are smarter than most threat actors.

If you could influence how governments approach cybersecurity, what three changes would you prioritize?

I cannot speak about a subject I know nothing about.

Which countries or regions appear to be the most cyber-resilient? What weaknesses do you see in countries that are less prepared?

It is completely random. You can find resilient systems where you least expect them and find loopholes in what were supposed to be impenetrable strongholds.

His answer highlights the difficulty of assessing cybersecurity maturity at the level of an entire country. Highly mature environments can exist alongside public infrastructure affected by legacy technology, insufficient funding or inconsistent security controls.

What makes a skilled security professional?

What separates a skilled cybersecurity professional from someone who simply knows how to exploit vulnerabilities?

Experience and a strong desire to learn. Read about vulnerability researchers such as James Kettle, James Forshaw and the many real hackers who make hacking what it is.

What advice would you give young people interested in cybersecurity and hacking?

Get more experience and fewer certificates. Doing Hack The Box Pro Labs will get you further than almost anything else, for a very small price.

His position is that formal credentials cannot replace repeated practical exposure to realistic environments.

Identity, privacy and the risk of arrest

Several reports circulating online claim to have identified you. How concerned are you about your safety and privacy? Has the possibility of being identified changed how you operate?

That never crossed my mind. The fact that there are “many” reports about my identity is, on the contrary, very reassuring. Even if someone managed to follow some breadcrumbs, it would be difficult to pinpoint my exact location because of how frequently I move and travel. I have a very nomadic lifestyle.

This statement cannot be independently verified. The civil identity associated with the ByteToBreach alias remains outside the scope of this article. Stop Ransomware is publishing the interview under the actor's public alias and is not endorsing any existing attribution.

Will he ever stop hacking?

Have you ever seriously considered retiring from hacking? What circumstances would convince you to stop?

I do not think I will ever stop hacking. Maybe I will stop cybercrime.

The distinction is significant. For ByteToBreach, hacking appears to be a permanent technical identity and intellectual interest. Cybercrime is described as one possible use of those abilities — one that he suggests he may eventually abandon, without making a commitment to do so.

What ByteToBreach claims happened at ANCPI

ByteToBreach denied reports that a ransom of EUR 10 million had been requested from ANCPI.

“I work alone, and I never asked for any ransom from ANCPI, let alone a crazy amount like EUR 10 million.”
ByteToBreach

He stated that his activity was financially motivated but did not explain precisely how he intended to monetize the intrusion if no ransom was requested.

He directed attention towards public posts in which he claims to have documented the intrusion. This article does not link directly to the marketplace on which those materials were posted.

“You can find most details of the intrusion in my posts. I developed the habit of documenting my steps to avoid denials from companies.”
ByteToBreach

Initial access and security weaknesses

Asked about the weaknesses used to compromise ANCPI, he said:

“The vulnerabilities exploited have been known for a long time.”
ByteToBreach

He did not provide a complete technical explanation during the interview, instead stating that the methods and vulnerabilities were documented in his posts and by the researchers who originally discovered them. The statement indicates a claim of known, rather than previously undisclosed, weaknesses; it does not independently establish the initial access vector.

Data exfiltration

ByteToBreach claims that cadastral data and source code belonging to several ANCPI systems were extracted.

“The cadastral data was not modified, only exfiltrated, together with the source code for various ANCPI IT systems.”
ByteToBreach

This is an important distinction, but it does not reduce the potential severity of the incident. Exfiltration affects confidentiality. Modification affects integrity. Each question must be investigated separately.

His statement that cadastral information was not modified cannot independently prove that the records remained intact. That determination requires forensic analysis, audit logs and comparison with trusted copies of the data.

Encrypted infrastructure

The actor also claims that several systems were completely encrypted.

“Some systems were fully encrypted, including SAN storage drives and the official website.”
ByteToBreach

He did not provide a direct answer confirming whether he personally performed every encryption action described.

He also assumed that ANCPI had off-site backups:

“Any serious infrastructure has off-site backups, and I do not think ANCPI is an exception.”
ByteToBreach

This was an assumption, not evidence that such backups existed, remained isolated from the incident or could be successfully restored.

Claims versus confirmed findings

Several important questions remain unresolved:

Only a complete forensic investigation can establish the full scope and impact of the incident.

Final thoughts

The most revealing statement in the interview may not be related directly to ANCPI.

“Attacking is much easier than defending a network with thousands of computers and an underfunded team.”
ByteToBreach

This does not excuse the intrusion or transfer responsibility away from the attacker.

It describes the imbalance confronting every large organization: the attacker needs one overlooked weakness, while the defensive team must continuously secure identities, endpoints, servers, applications, network infrastructure and backups.

Listening to the attacker's perspective does not mean legitimizing his actions. It means understanding how targets are selected, how intrusions are rationalized and what defenders may be facing before the next incident occurs.

By Bogdan Albei · Stop Ransomware · Published 20 July 2026

The identity of the individual behind the ByteToBreach account has not been independently verified, and Stop Ransomware does not endorse any existing attribution. Statements concerning ANCPI are the actor's own claims and must not be treated as confirmed forensic findings. Operational details that could facilitate additional attacks have not been included; Stop Ransomware does not link to illicit marketplaces or publish credentials, active endpoints or exploitation instructions.

The attacker needs one overlooked weakness.

As ByteToBreach puts it, attacking is easier than defending. The free Security Checkup shows you what is actually visible and exploitable in your environment — before someone else looks.

Book your free Security Checkup