Four Years for Four Figures: Romanian Hacker Sold Oregon Government Access for $3,000 in Bitcoin

Catalin Dragomir's cut-rate credentials marketplace cost him 56 months in a U.S. federal prison — and exposed just how cheaply critical infrastructure can change hands.

Written by OutOfToken AI

June 7, 2026 · 4 min read · Synthesized from reporting by DataBreaches.net · How this works

AI Likely Accurate · 8/10

A federal court has sentenced 46-year-old Romanian national Catalin Dragomir to 56 months in prison for breaching an Oregon state government office's network in 2021 and auctioning off that access for a mere $3,000 in Bitcoin. The case cuts to the heart of a persistent and underreported threat vector: initial access brokers who commoditize network intrusions, selling the keys to government and enterprise systems to the highest — or simply the quickest — bidder. Dragomir's arrest in Romania in November 2024 and subsequent extradition to the United States marked a rare moment of transatlantic accountability in a landscape where most such actors operate with impunity.

The Mechanics of a Cut-Rate Intrusion

According to court documents and a Department of Justice press release dated May 27, Dragomir, formerly of Constanta, Romania, compromised the network of an Oregon state government office along with other U.S.-based victims. The intrusion occurred in 2021, during a period when remote work expansions had dramatically widened attack surfaces across public sector infrastructure. Dragomir did not deploy ransomware or exfiltrate bulk data for personal exploitation — his business model was more surgical and arguably more dangerous: he harvested valid network credentials and sold them on underground markets, effectively outsourcing the destructive phase to whoever came next.

Initial Access Brokerage: The Dark Web's Wholesalers

The initial access broker ecosystem has matured considerably since its early days. Actors like Dragomir function as wholesalers in a tiered criminal economy — they handle the technically demanding work of exploitation and persistence, then monetize that foothold rather than risking further exposure. A $3,000 Bitcoin transaction for validated government network credentials is, by dark web market standards, a modest but not unusual price point for a mid-tier public sector target. Ransomware gangs and state-aligned threat actors routinely purchase such access to skip the resource-intensive reconnaissance and exploitation phases. That a state government office could be compromised and resold for less than a used car underscores the asymmetric economics driving the cybercrime supply chain.

"$3,000 in Bitcoin — that's what validated access to an Oregon state government network fetched on the underground market in 2021. The buyer's identity and ultimate intentions remain publicly undisclosed."

Extradition as Signal, Not Solution

Dragomir's journey from Romania to a U.S. federal courtroom required international law enforcement coordination and took years from the original compromise to sentencing. He was arrested in Romania in November 2024 — more than three years after the breach itself. The successful extradition is a meaningful signal that U.S. prosecutors are willing to pursue foreign nationals well beyond their borders, even for crimes that might be considered lower-tier in the ransomware era. Still, the timeline illustrates the structural lag that defines international cybercrime prosecution: by the time a sentence is handed down, the tactics, markets, and actors involved have often evolved two or three generations further. The 56-month sentence — just under five years — reflects the seriousness with which the DOJ is treating access brokerage as a distinct and prosecutable crime category, not merely a precursor offense.

Dragomir's sentencing arrives as U.S. federal agencies continue to press for stronger cross-border enforcement frameworks and as state governments face mounting pressure to audit their network security postures. The Oregon case is a reminder that the weakest link in critical infrastructure security is often not the firewall but the credential — and that there is an entire underground economy built around harvesting and reselling exactly that. As long as the gap between the cost of exploitation and the value of access remains this wide, initial access brokers will keep finding buyers. The question is whether law enforcement can close that gap faster than the market can replace players like Dragomir.

Editorial Note

DataBreaches.net is a reputable cybersecurity news aggregator that primarily reports on official DOJ press releases and court documents. The May 2021 timeframe and sentencing details are consistent with documented cases of cybercriminal activity targeting U.S. government entities. The specific mention of a DOJ press release as source material adds credibility, though independent verification of the DOJ announcement would confirm details.

Claim Tracker

AI-assessed

VerifiedCatalin Dragomir was sentenced to 56 months in prison

Confirmed by DOJ press release dated May 27 per article

VerifiedDragomir sold access to an Oregon state government office for $3,000 in Bitcoin

Stated in both title and body; sourced from court documents

UnverifiedDragomir was arrested in Romania in November 2024

Claimed in article but arrest date differs significantly from 2021 intrusion; requires independent confirmation

UnverifiedThe intrusion occurred during a period when remote work expansions had widened attack surfaces

General contextual claim about 2021 conditions; not specific to this case and somewhat speculative

UnverifiedInitial access brokers represent an 'underreported threat vector'

Opinion-based characterization presented as fact; lacks data supporting 'underreported' claim

Ask AI about this story

// discussion

sign in to join the discussion