Over the weekend of December 21–22, 2025, attackers encrypted approximately 1,000 computer systems at Administrația Națională Apele Române (Romanian Waters), the country’s national water management authority. The attack reached the central organization and 10 of its 11 regional offices, disabling geographic information systems (GIS) servers, databases, email, web services, Windows workstations, and domain name servers. The method was BitLocker, the Windows full-disk encryption tool: by abusing a legitimate operating system feature rather than deploying custom ransomware, the attackers avoided signature-based detection. A ransom note demanded contact within seven days; no attacker or ransomware group has claimed responsibility and no payment amount was disclosed.
Romania’s National Directorate of Cyber Security (DNSC) confirmed that operational technologies were unaffected. Hydrotechnical facilities — dams, flood retention structures, and flood-defense infrastructure — continued operating normally throughout the incident. Dispatching and coordination of those structures shifted to telephone and radio communications after the IT disruption. The National Cyber Security Directorate stated that “hydrotechnical facilities are safe and they are locally operated by on-site personnel coordinated via the dispatch centres.” The SRI’s National Cyberint Center, DNSC, and other Romanian security agencies opened an investigation. The initial access vector had not been identified at the time of disclosure.
Romanian Waters manages the country’s river basins, flood-risk monitoring, and water-resource allocation. Disruption to its GIS infrastructure affects the agency’s situational awareness during flood events — a meaningful operational risk in a country where the Danube basin and Carpathian rivers are subject to seasonal flooding, though no adverse weather event coincided with this incident. The attack follows two other significant ransomware hits on Romanian critical-infrastructure operators within days: the Oltenia Energy Complex Gentlemen ransomware attack on December 26 and the subsequent Conpet pipeline Qilin breach in early February 2026. All three were contained to administrative IT layers with no confirmed OT or process-system compromise, but the concentration suggests Romania’s critical-infrastructure operators are operating under sustained ransomware targeting pressure.
The BitLocker-as-ransomware technique reduces the attacker’s tooling footprint to near zero but limits recovery options: without the BitLocker recovery key, which the attacker holds, encrypted volumes cannot be unlocked short of a full system rebuild from backup. Bitdefender documented this technique earlier in 2025 under the name ShrinkLocker, finding it used by multiple unaffiliated threat actors across manufacturing, pharmaceutical, and government targets in Romania, Indonesia, and Jordan. The structural risk for water utilities running GIS and dispatch systems on Windows infrastructure is the same as for any IT-dependent operator: an attacker who reaches the domain controller can enable BitLocker across an entire organization without deploying a single piece of novel malware.