Lithuania Registry Breach Exposes 600,000 Records
Coverage from The Record, Tech Times, and others
Articles
4
Active Days
58
The Topic

Lithuanian authorities are investigating the theft of more than 600,000 records from state property and legal-entity registries after attackers misused credentials belonging to authorized institutions. The exposed data included names, dates of birth, national identification numbers and property addresses, while authorities said financial information and several categories of official documents were not accessed. The incident prompted account blocking, credential resets, leadership changes and renewed scrutiny of Lithuania’s state IT security and disclosure practices, while foreign or Russian involvement remains unconfirmed.
First Article: 05/25/26
Latest Article: 07/21/26
Summary
- More than 600,000 records from Lithuania’s Real Estate and Legal Entities Registers were accessed without authorization.
- The attack used credentials assigned to institutions with legitimate registry access rather than a confirmed direct compromise of the Centre of Registers.
- Exposed information included names, dates of birth, national identification numbers and property addresses.
- Authorities said phone numbers, email addresses, bank and payment data, court rulings and cadastral files were not exposed.
- Lithuania blocked suspected accounts and required users to update credentials after detecting the breach in early April 2026.
- Centre of Registers chief Adrijus Jusas resigned, while officials cited prolonged underinvestment in state IT infrastructure.
- Officials and politicians raised possible foreign or Russian involvement, but prosecutors and security services had not confirmed attribution.
History
The story now adds a confirmed leadership consequence and a broader institutional/regulatory context: the Centre of Registers chief resigned, and authorities are linking the breach to wider state IT weaknesses while still withholding attribution. The framing also shifts slightly from a single registry intrusion to a more explicit credential-based data theft with renewed suspicion of possible foreign involvement.
