Following his public claim of responsibility for the cyberattack affecting Romania's National Agency for Cadastre and Land Registration (ANCPI), I contacted the threat actor known as ByteToBreach.
He agreed to answer questions about his motivations, personal principles, target selection, views on the cybersecurity industry and the incident involving ANCPI. His answers were often brief, but direct. He describes himself as financially motivated, politically unaffiliated and driven by curiosity and the desire to learn.
He also denies requesting a EUR 10 million ransom from ANCPI and claims that cadastral data was exfiltrated but not modified.
Editorial note
The interview was conducted through Telegram. Answers have been lightly edited for spelling, grammar and clarity without changing their meaning.
The identity of the individual behind the account has not been independently verified. Statements concerning ANCPI are the actor's own claims and must not be treated as confirmed forensic findings.
Operational details that could facilitate additional attacks have not been included. Stop Ransomware does not link directly to illicit marketplaces or publish credentials, active endpoints or exploitation instructions.
Curiosity, learning and money
What first sparked your interest in hacking and cybersecurity? Was there a particular event, frustration or curiosity that pushed you towards it?
Curiosity.
Was there a specific incident in your life or in the news that strengthened your interest in this direction?
Nothing in particular.
Hackers frequently mention financial gain, ideology, revenge, technical challenges or a sense of justice. Which of these motivations resonate most with you?
My main motivation is money.
How important is recognition within the hacking community compared with financial outcomes?
Recognition is only important to me while attending DEF CON. Otherwise, I keep my identity private.
Despite identifying money as his primary motivation, ByteToBreach later explained that the learning experience itself remains an important part of his activity.
Which previous operation gave you the strongest sense of purpose or satisfaction?
Most operations give me a strong sense of satisfaction because of the learning experience. Money is a strong driver, but I am also very content with simply learning.
Attacking versus defending
How does the feeling of outsmarting large, well-funded organizations influence your motivation?
I could not say, because I have never outsmarted anyone. Attacking is much easier than defending a network with thousands of computers and an underfunded team.
His answer rejects the common image of the attacker as a technical mastermind defeating a perfectly secured organization. Instead, he points to the basic asymmetry between attackers and defenders: an attacker needs to identify one viable path, while a defensive team must protect a large and constantly changing environment.
What frustrates you most about the state of cybersecurity in government institutions?
Lack of funding.
When discussing the ANCPI incident, he returned to the same point and defended the people responsible for protecting large environments.
“Protecting a network, especially from the inside, is not an easy task. People should not be so hard on IT teams that work hard and overtime to keep everything under control. It does not excuse anything, but at least it helps people understand the issues better.”
Politics, faith and personal principles
How would you describe your political beliefs? Have they influenced your actions or target selection?
No politics.
Do you have personal values or principles that guide your decisions, both online and offline?
Christianity. The desire to learn.
At the end of the interview, when asked what message he would send to policymakers, cybersecurity professionals and ordinary internet users, his response was religious rather than technical:
“Stay faithful to Jesus Christ, our one true Savior and Lord.”
He did not address the apparent contradiction between his declared religious beliefs and his admission that he engages in financially motivated cybercrime.
How targets are selected
Why do you choose certain targets over others?
I decide on a whim.
The answer suggests that at least some of his activity is opportunistic rather than driven by a defined political, ideological or strategic objective.
Regarding ANCPI, he said the operation had a single motivation:
“It was financially motivated, nothing more.”
He also stated that he documents intrusions publicly because organizations may otherwise deny that a compromise occurred.
“I developed the habit of documenting my steps to avoid denials from companies.”
A line he says he will not cross
Is there anything you regret or any line you have deliberately chosen not to cross?
Hospitals, because of how dangerous it can be. During attacks involving healthcare systems in Brazil, I blacklisted entire subnets to avoid accidentally communicating with patient systems. I would rather not do it again.
This claim has not been independently verified. Avoiding hospitals does not remove the potential harm caused by attacks against other institutions, organizations or individuals. It does, however, indicate that he draws a distinction between targets based on the immediate risk to human life.
Governments and the cybersecurity industry
Do governments and law-enforcement agencies understand the current cyber-threat landscape, or are they constantly one step behind?
Yes, they understand it. Most ethical hackers are smarter than most threat actors.
If you could influence how governments approach cybersecurity, what three changes would you prioritize?
I cannot speak about a subject I know nothing about.
Which countries or regions appear to be the most cyber-resilient? What weaknesses do you see in countries that are less prepared?
It is completely random. You can find resilient systems where you least expect them and find loopholes in what were supposed to be impenetrable strongholds.
His answer highlights the difficulty of assessing cybersecurity maturity at the level of an entire country. Highly mature environments can exist alongside public infrastructure affected by legacy technology, insufficient funding or inconsistent security controls.
What makes a skilled security professional?
What separates a skilled cybersecurity professional from someone who simply knows how to exploit vulnerabilities?
Experience and a strong desire to learn. Read about vulnerability researchers such as James Kettle, James Forshaw and the many real hackers who make hacking what it is.
What advice would you give young people interested in cybersecurity and hacking?
Get more experience and fewer certificates. Doing Hack The Box Pro Labs will get you further than almost anything else, for a very small price.
His position is that formal credentials cannot replace repeated practical exposure to realistic environments.
Identity, privacy and the risk of arrest
Several reports circulating online claim to have identified you. How concerned are you about your safety and privacy? Has the possibility of being identified changed how you operate?
That never crossed my mind. The fact that there are “many” reports about my identity is, on the contrary, very reassuring. Even if someone managed to follow some breadcrumbs, it would be difficult to pinpoint my exact location because of how frequently I move and travel. I have a very nomadic lifestyle.
This statement cannot be independently verified. The civil identity associated with the ByteToBreach alias remains outside the scope of this article. Stop Ransomware is publishing the interview under the actor's public alias and is not endorsing any existing attribution.
Will he ever stop hacking?
Have you ever seriously considered retiring from hacking? What circumstances would convince you to stop?
I do not think I will ever stop hacking. Maybe I will stop cybercrime.
The distinction is significant. For ByteToBreach, hacking appears to be a permanent technical identity and intellectual interest. Cybercrime is described as one possible use of those abilities — one that he suggests he may eventually abandon, without making a commitment to do so.
What ByteToBreach claims happened at ANCPI
ByteToBreach denied reports that a ransom of EUR 10 million had been requested from ANCPI.
“I work alone, and I never asked for any ransom from ANCPI, let alone a crazy amount like EUR 10 million.”
He stated that his activity was financially motivated but did not explain precisely how he intended to monetize the intrusion if no ransom was requested.
He directed attention towards public posts in which he claims to have documented the intrusion. This article does not link directly to the marketplace on which those materials were posted.
“You can find most details of the intrusion in my posts. I developed the habit of documenting my steps to avoid denials from companies.”
Initial access and security weaknesses
Asked about the weaknesses used to compromise ANCPI, he said:
“The vulnerabilities exploited have been known for a long time.”
He did not provide a complete technical explanation during the interview, instead stating that the methods and vulnerabilities were documented in his posts and by the researchers who originally discovered them. The statement indicates a claim of known, rather than previously undisclosed, weaknesses; it does not independently establish the initial access vector.
Data exfiltration
ByteToBreach claims that cadastral data and source code belonging to several ANCPI systems were extracted.
“The cadastral data was not modified, only exfiltrated, together with the source code for various ANCPI IT systems.”
This is an important distinction, but it does not reduce the potential severity of the incident. Exfiltration affects confidentiality. Modification affects integrity. Each question must be investigated separately.
His statement that cadastral information was not modified cannot independently prove that the records remained intact. That determination requires forensic analysis, audit logs and comparison with trusted copies of the data.
Encrypted infrastructure
The actor also claims that several systems were completely encrypted.
“Some systems were fully encrypted, including SAN storage drives and the official website.”
He did not provide a direct answer confirming whether he personally performed every encryption action described.
He also assumed that ANCPI had off-site backups:
“Any serious infrastructure has off-site backups, and I do not think ANCPI is an exception.”
This was an assumption, not evidence that such backups existed, remained isolated from the incident or could be successfully restored.
Claims versus confirmed findings
Several important questions remain unresolved:
- The initial access vector has not been independently confirmed.
- The exact nature and volume of the allegedly exfiltrated data remain unclear.
- There is no independent confirmation within this interview that cadastral records were not modified.
- It has not been established whether the allegedly extracted data has already been sold or shared with another party.
- The extent of the encryption and the systems affected has not been independently verified.
- The widely circulated claim that ANCPI received a EUR 10 million ransom demand is explicitly denied by ByteToBreach, but the complete communication between the actor and the institution is not publicly available.
Only a complete forensic investigation can establish the full scope and impact of the incident.
Final thoughts
The most revealing statement in the interview may not be related directly to ANCPI.
“Attacking is much easier than defending a network with thousands of computers and an underfunded team.”
This does not excuse the intrusion or transfer responsibility away from the attacker.
It describes the imbalance confronting every large organization: the attacker needs one overlooked weakness, while the defensive team must continuously secure identities, endpoints, servers, applications, network infrastructure and backups.
Listening to the attacker's perspective does not mean legitimizing his actions. It means understanding how targets are selected, how intrusions are rationalized and what defenders may be facing before the next incident occurs.
By Bogdan Albei · Stop Ransomware · Published 20 July 2026
The identity of the individual behind the ByteToBreach account has not been independently verified, and Stop Ransomware does not endorse any existing attribution. Statements concerning ANCPI are the actor's own claims and must not be treated as confirmed forensic findings. Operational details that could facilitate additional attacks have not been included; Stop Ransomware does not link to illicit marketplaces or publish credentials, active endpoints or exploitation instructions.