71% of reported incidents hit one sector — what the concentration in Romania's national cyber report means for financial entities

71% of reported incidents hit one sector — what the concentration in Romania's national cyber report means for financial entities

The 2025 activity report from Romania's National Cyber Security Directorate (DNSC), approved by CSAT Decision no. 117 of 7 August 2026, was covered in the press for its growth figures: ransomware up 153%, phishing up 70.6%, account compromise up 353%. The number that says most about where budget should go in 2026 is not a growth figure at all. It is a distribution.

Across the sectors the report analyses, reported incidents break down like this:

  • banking — 71.09%
  • postal and courier services — 10.8%
  • financial market infrastructures — 6.34%

Nearly nine in ten reported incidents land in three sectors that together form a single chain: money, the movement of money, and the delivery of goods bought with it. In both of the dominant sectors — banking and courier — DNSC states that phishing attacks predominated.

Concentration is not the same as negligence

The first wrong reading of those percentages is that banks are worse defended. Almost certainly the reverse is true. Romanian banking is among the most heavily regulated and best-resourced parts of the economy, with real security teams, and reporting that is both mandatory and actually enforced. Part of the 71.09% reflects the fact that banks report, while other sectors still do not.

The second wrong reading is that the rest of the economy is safe. The concentration describes where incidents are reported, not where they happen.

The useful reading is the third one. Attackers choose targets by return, and in Romania the return is in financial services and the infrastructure that serves them. That changes the nature of the threat. An organisation hit opportunistically defends itself with technical hygiene. An organisation selected deliberately, by actors who picked it on expected profit, defends itself with adversarial testing and rehearsed plans.

Why courier services come second

The 10.8% held by postal and courier services looks out of place next to banking until you look at how the attacks work.

A delivery notification is one of the most effective phishing pretexts available, because it is a message almost anyone is genuinely expecting in a given week. It asks the victim to believe nothing improbable. And the target of these campaigns is not the parcel — it is the card details or credentials entered on a fake page asking the recipient to "reconfirm the delivery fee".

Two practical consequences follow. For logistics operators, the brand itself is the asset under attack, even when their own infrastructure is untouched — which makes look-alike domain monitoring and abuse reporting part of security rather than marketing. For banks, part of the fraud recorded against customer accounts starts in a message impersonating a courier rather than a bank — which is a plausible reason the two sectors sit next to each other in the report, with phishing dominant in both.

The 353% rise in account compromise, from 248 to 1,125 incidents, is attributed in the report to campaigns run over WhatsApp, password reuse, and missing multi-factor authentication. Same chain, seen from the other end.

Obligations that already apply

Financial entities in Romania sit under two regimes at once, and their reporting clocks do not match.

NIS 2, transposed through Government Emergency Ordinance no. 155/2024 and consolidated by Law no. 124/2025, with DNSC Orders no. 1/2025 and no. 2/2025 in force since 20 August 2025. Significant incidents are reported through the national PNRISC platform: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. Penalties reach EUR 10,000,000 or 2% of worldwide annual turnover for essential entities, and EUR 7,000,000 or 1.4% for important ones. Responsibility for approving and overseeing risk-management measures sits explicitly with management.

DORA, Regulation (EU) 2022/2554, applicable since 17 January 2025 to financial entities — banks, investment firms, payment institutions, insurers, fund managers, crypto-asset service providers. For a major ICT-related incident, the initial notification is due within 4 hours of classifying the incident as major, and no later than 24 hours from becoming aware of it; the intermediate report within 72 hours; the final report within one month.

The gap between 24 hours under NIS 2 and 4 hours under DORA is not a legal subtlety. It is the difference between a process you can improvise and one you have to rehearse. The four-hour window is consumed almost entirely by the classification decision, if nobody has settled in advance who makes it and against what criteria.

DORA also introduces threat-led penetration testing (TLPT), built on the TIBER-EU framework, required at least once every three years for entities designated by the competent authority. In Romania those authorities are the National Bank of Romania and the Financial Supervisory Authority, depending on entity type. TLPT is not simply a longer penetration test: it uses scenarios built from real threat intelligence, run against critical functions in production, with a blue team that does not know the test is happening.

Four priorities that follow from the numbers

1. Test the exposed channels, not the theoretical perimeter. Internet banking, the mobile app, payment APIs, the customer self-service portal and the interfaces exposed toward processors are the surface an attacker who has chosen you will work on. A penetration test against those components and the APIs behind them answers a question a documentary audit never reaches: what actually happens when someone tries.

2. Calibrate phishing simulations to the real sector. DNSC states explicitly that messages are now written in correct Romanian and faithfully reproduce the visual identity of legitimate organisations. If your templates still carry deliberate grammatical errors as a difficulty dial, you are measuring a cue that no longer appears. The scenarios that matter here are the courier notification, the payment confirmation, the message from the "anti-fraud department", and delivery over WhatsApp rather than email alone. A simulation programme built on those patterns measures real risk, and human risk management turns the result into an intervention rather than a report.

3. Test continuity plans, not just backups. The attack on Romania's National Water Administration blocked almost the entire activity of the institution and its territorial structures for roughly a week. The useful question is not whether you have backups, but whether you have ever restored from them under time pressure, with whoever is on shift, on a Friday.

4. Rehearse the reporting before you need it. Who classifies the incident, against what criteria, who signs the notification, who files it in PNRISC, and who speaks to the National Bank or the Financial Supervisory Authority. A tabletop exercise with management once a year is the only reasonable way to have those answers before hour four.

The concentration in the DNSC report carries a simple message: if you are in Romanian financial services, you are not the target of a volume campaign. You are the target of someone who did the arithmetic. Security audit and compliance assessment are useful as structure, but the 2025 figures suggest the part most often missing is verification through actual testing.

This article is general information and does not constitute legal or regulatory advice. For how NIS 2 or DORA classify your specific entity, consult the competent authority and your legal counsel.

Sources: DNSC 2025 activity report, approved by CSAT Decision no. 117 of 7 August 2026 — summary via Economedia; DNSC; Regulation (EU) 2022/2554 — DORA; Directive (EU) 2022/2555 — NIS 2. Sector percentages and incident counts come from the public version of the DNSC report as presented by Romanian business press; the full document remains the reference for any formal use.

Back to blog