Lithuanian authorities are investigating the leak of more than 600,000 records from national registers. For residents and companies, the immediate issue is not panic but checking whether personal, property or business information could be used for fraud, pressure or convincing fake messages.

The Associated Press reported on May 25, 2026, that the incident was mainly linked to Lithuania’s Real Estate Register and Register of Legal Entities. The head of the Centre of Registers, Adrijus Jusas, resigned. The Centre of Registers is the state-owned body that manages major public registers in Lithuania.

According to publicly reported information, Lithuanian institutions are investigating possible access to national register data through institutional logins. That means the inquiry has to establish not only what data was taken, but also whether legitimate access credentials were abused.

Possible involvement by a foreign state has been described as a suspicion, not a final conclusion. Until the investigation is complete, the safest approach is to rely on official statements and avoid unverified lists, links or searches claiming to show “leaked data”.

For individuals, the risk may come from the use of addresses, property links, ownership records or other registry details in social engineering. Fraudsters may send messages that appear personal because they mention a real address, property, company name or job title.

For businesses, the Register of Legal Entities is especially relevant. Information about directors, shareholders, registered offices, contacts or representation rights can be used in fake invoices, pressure on accounting teams, executive impersonation emails, and attempts to take over domains or accounts.

Change passwords on accounts where you reused the same password as for work, company or public-service systems.
Turn on two-factor authentication for email, banking, accounting, domain and cloud accounts.
Review who in your organisation has access to registers, email, document storage and accounting systems.
Check whether your data may have leaked, and review suspicious logins, email forwarding rules or newly added administrators.
Warn employees not to approve payments or data changes based only on an email request.

A suspicious email may look credible because it contains a real address, company code or property detail. That does not mean the sender is a public authority or a legitimate business partner.

Pause if a message asks you to log in urgently through a link, update data, pay a “fine”, send documents or change a bank account. Verify such requests through a separate channel: call a known number or go to the official website directly, rather than using a link in the message.

Follow statements from the Centre of Registers, Lithuania’s Prosecutor General’s Office and national cybersecurity authorities. If you receive a message saying you must “check leaked data”, do not open attachments or enter login details.

Important new information would include an officially confirmed list of affected registers, the relevant time period and the categories of data involved.

Context & actions
About this article

Report
Share

Source check
Šaltinio pagrindas

Straipsnyje atskiriami patvirtinti faktai nuo dar tiriamų įtarimų dėl prieigos ir galimo užsienio valstybės vaidmens.

Checks

Patikrintas paskelbtas nutekėjimo mastas: daugiau kaip 600 000 įrašų
Atskirti minimi registrai: Nekilnojamojo turto ir Juridinių asmenų registrai
Užsienio valstybės dalyvavimas įvardytas tik kaip įtarimas
Praktiniai patarimai suformuluoti be teiginio, kad visi gyventojai nukentėjo

SourceAssociated Press

ScopeLietuva

Updated2026-05-29 17:53

Report

Article contextPeople & topics#6