Lithuania’s Registry Centre built notification system after discovering data breach

Friday 29th May 2026 on 13:00 in Lithuania Lithuania

cybersecurity, data breach, lithuania

The acting head of Lithuania’s Centre of Registers (RC) said the institution developed a public notification system only after learning of a large-scale real estate registry data leak, national broadcaster LRT reported on Thursday.

Giedrius Cininas, temporarily leading the RC, told journalists that the system—allowing residents to check if their personal data was compromised—should ideally have launched when the Prosecutor General’s Office announced its pre-trial investigation. “I believe the RC was obligated to inform the public because we had a personal data security incident,” he said after an emergency parliamentary committee meeting. “The question was how and when to notify people without unjustified delay.”

The online tool for checking affected records went live on the RC website Monday evening. Public frustration had mounted over the lack of immediate transparency, prompting the Prosecutor General’s Office to clarify on Wednesday that the RC, not prosecutors, was responsible for disclosing the breach.

The investigation into the suspected leak of real estate registry data was announced last Friday, though prosecutors later specified it began on April 15, the same day they received the RC’s report. Cininas said the RC first detected suspicious logins in early April, blocked several accounts, and spent roughly 10 days gathering evidence before alerting law enforcement. “We suspected unlawful activity and needed to assess the scale before reporting it,” he explained.

Economy and Innovation Minister Edvinas Grikšas confirmed his ministry learned of initial leaks on April 3 but only grasped the full extent—hundreds of thousands of records—on April 21. Prime Minister Ingrida Šimonytė’s office was also briefed in early April, while Justice Minister Rita Tamašunienė said she received details on April 10.

Police have since confirmed the data was exfiltrated via the Migration Department, overseen by the Interior Ministry. The RC itself falls under the Economy Ministry, though legal oversight of registries belongs to the Justice Ministry.

Interior Minister Vladislavas Kondratovičius revealed that in mid-February, a citizen inquired why Migration Department staff were accessing their property records, triggering suspicions of a breach. Two department employees were later identified as having misused data.

Source 
(via LRT)