# Romanian Hacker Sentenced to 56 Months for Selling Access to Oregon State Network


Catalin Dragomir receives significant federal prison sentence after pleading guilty to breaching government systems and selling network access worth over $250,000


A 45-year-old Romanian national has been sentenced to four years and eight months in federal prison for hacking into an Oregon state government office's network and selling unauthorized access to that system and others across the United States. The case underscores the persistent threat of international cybercriminals targeting government infrastructure and the expanding market for network access sales among threat actors.


Catalin Dragomir was arrested in Romania in November 2024 and extradited to the United States in January 2025. In February 2026, he pleaded guilty to one count of obtaining information from a protected computer and one count of aggravated identity theft. This week, the federal judge imposed the prison sentence, crediting Dragomir with two months of time served during his detention in Romania.


## The Breach and Access Sales


According to the U.S. Justice Department, Dragomir successfully infiltrated the network of an Oregon state government office in June 2021. Rather than deploying ransomware or conducting data exfiltration himself, he monetized the access by selling it to other cybercriminals. The hacker negotiated a sale of the Oregon network access for $3,000 in Bitcoin to an undisclosed buyer.


However, the Oregon breach was not an isolated incident. Prosecutors revealed that Dragomir had compromised at least 10 additional organizations across the United States and sold access to their networks as well. When aggregated, these breaches resulted in cumulative losses exceeding $250,000, demonstrating the significant financial damage inflicted through network access sales.


## Legal Proceedings and Extradition


The case highlights growing international cooperation in prosecuting cybercriminals. After Romanian authorities arrested Dragomir, U.S. officials successfully negotiated his extradition—a process that can be protracted with nations that lack robust mutual legal assistance agreements with the United States. The extradition was completed in January 2025, placing Dragomir into federal custody.


During his guilty plea proceeding in February 2026, Dragomir admitted to the charges. However, he attempted to minimize his culpability by claiming he had worked as a contractor for another hacker rather than serving as the scheme's architect or mastermind. Prosecutors characterized him as "prolific" in their sentencing memoranda, indicating that his involvement spanned multiple breaches and was not limited to the Oregon case alone.


## Network Access as a Criminal Currency


The sale of network access has become a lucrative criminal enterprise. Threat actors who excel at initial access—breaking into corporate and government networks—frequently monetize that skill by selling credentials, VPN access, or direct remote desktop protocol (RDP) access to other criminals. This creates a supply chain of compromise: initial access brokers (IABs) breach networks and sell access to downstream buyers who may deploy ransomware, conduct data exfiltration, or conduct espionage.


The $3,000 price tag for Oregon state network access is consistent with market rates observed in criminal forums. Security researchers monitoring the dark web have documented that network access to mid-sized government agencies and corporations typically ranges from $1,000 to $10,000 depending on network criticality, privilege level of the compromised account, and geographic jurisdiction.


## Government Networks as High-Value Targets


State government networks present attractive targets for cybercriminals for several reasons:


  • Data value: State systems contain personally identifiable information (PII), financial records, and sensitive agency databases with substantial resale value
  • Access scope: A foothold in state infrastructure may provide lateral movement opportunities to multiple agencies and departments
  • Remediation lag: Government IT budgets and incident response capabilities vary widely; some state agencies lack mature security operations
  • Regulatory implications: Breaches of government systems trigger federal law enforcement involvement and multi-agency investigations, potentially attracting higher-profile buyers

  • The compromise of an Oregon state office in 2021 likely provided access to administrative accounts, employee directories, and potentially agency-specific data repositories.


    ## The Broader Threat Landscape


    Dragomir's case is not anomalous. Security researchers and law enforcement have documented significant uptick in network access sales since 2020. The trend accelerated during the pandemic when remote access demand surged, and threat actors capitalized on poorly secured VPN appliances and unpatched edge devices.


    Recent precedents include:


    | Case | Perpetrator | Target | Year | Outcome |

    |------|------------|--------|------|---------|

    | Karakurt negotiator sentencing | Mikhail Matveev | Multiple organizations | 2022 | Extradited, sentenced |

    | DraftKings hacker | Unknown IAB | Sports betting platform | 2023 | Prosecuted |

    | Dutch port breach | Unknown attacker | Rotterdam port authority | 2022 | Sentenced |


    ## Implications for State and Local Governments


    The Dragomir case carries several uncomfortable implications for state agencies nationwide:


    Persistent vulnerability: The 2021 Oregon breach occurred over five years ago. The extended timeline between compromise and prosecution illustrates how long threat actors can maintain persistence undetected, and how many downstream criminal groups may have purchased and exploited the same access.


    Limited detection: Dragomir's activity only came to light after law enforcement investigation, not through the victim agency's own security monitoring. This suggests limited intrusion detection capabilities within some state IT infrastructure.


    International prosecution complexity: While international cooperation succeeded in this case, many similar breaches go unprosecuted due to extradition challenges or attribution difficulties.


    ## Technical Recommendations for Defenders


    Organizations—particularly government entities—should implement the following controls to prevent unauthorized network access sales:


  • Multi-factor authentication: Enforce MFA on all remote access solutions (VPN, RDP, SSH) to prevent credential-based intrusions
  • Network segmentation: Isolate critical systems and limit lateral movement by implementing zero-trust architecture
  • EDR/XDR deployment: Deploy endpoint detection and response tools to identify suspicious lateral movement and data exfiltration attempts
  • Regular audits: Conduct quarterly reviews of active network sessions, privileged account usage, and VPN access logs
  • Threat hunting: Actively search for signs of compromise, focusing on dormant accounts, unusual privilege escalations, and off-hours access

  • ## HackWire Analysis


    The Dragomir sentencing reflects a strategic shift in U.S. law enforcement: targeting the initial access broker tier of the criminal supply chain. Rather than pursuing downstream ransomware gangs—which often operate across jurisdictions and dissolve rapidly—prosecutors focus on the specialized hackers who breach networks and sell access.


    This approach makes prosecutorial sense: removing prolific IABs disrupts the entire ecosystem. If access brokers face 56-month federal sentences and international extradition, the return-on-investment calculus for new entrants shifts. However, the case also reveals the time lag inherent in prosecution—Dragomir compromised systems in 2021 but wasn't arrested until November 2024, nearly four years later. In that interval, countless organizations likely purchased and exploited the same access without any awareness of the breach.


    The real lesson is that government agencies cannot rely on law enforcement prosecution as a security control. The average dwell time for network access sales remains measured in months or years. Defenders need to assume compromise and implement detection-focused controls rather than hoping attackers are eventually caught. For state agencies particularly—which often lag in security maturity compared to federal entities—this case should trigger an urgent audit of remote access controls, VPN infrastructure, and identity management systems.


    The message to other IABs should be clear: the U.S. will pursue extradition and prosecute network access sales. Whether that message is heeded by the next generation of Romanian, Russian, or Chinese initial access brokers remains to be seen.


    HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)