Access Broker, Federal Prisoner: Romanian Hacker Catalin Dragomir Gets 56 Months for Oregon Gov't Network Breach
A 45-year-old Romanian national who sold backdoor access to an Oregon state government network learned the hard way that U.S. federal prosecutors have a long reach.
Written by OutOfToken AI
June 6, 2026 · 4 min read · Synthesized from reporting by BleepingComputer · How this works
Catalin Dragomir, a 45-year-old Romanian national, was sentenced this week to 56 months in a U.S. federal prison after breaking into an Oregon state government computer network and monetizing that access on the criminal marketplace. Extradited from Romania to face charges stateside, Dragomir's case is a textbook example of the access-broker model — hack the target, sell the keys, collect the cash — and the increasingly aggressive international cooperation that's putting that business model behind bars.
The Access Broker Playbook
Dragomir didn't just compromise the Oregon government network for personal gain — he packaged and sold that access to others, a practice that has become one of the most corrosive forces in the modern threat landscape. Access brokers sit at the top of the cybercriminal supply chain, doing the technically demanding work of initial intrusion and then offloading credentials, VPN footholds, or remote desktop sessions to ransomware groups and other bad actors who lack the skill or patience to breach networks themselves. In Dragomir's case, the victims extended well beyond Oregon, with federal prosecutors documenting cyberattacks targeting dozens of additional U.S. victims — a downstream consequence that illustrates exactly why courts treat access brokerage as a multiplier offense.
The Charges and the Sentence
Federal prosecutors brought a computer intrusion count carrying a maximum five-year sentence, paired with a mandatory consecutive two-year term for aggravated identity theft — a combination that could have landed Dragomir behind bars for the better part of a decade. The court ultimately handed down 56 months, falling just under that five-year ceiling on the primary count, along with a potential fine of up to $250,000 and three years of supervised release to follow incarceration. The identity theft component is particularly significant: mandatory consecutive sentencing on that charge is a prosecutorial tool specifically designed to prevent judges from absorbing it into a lighter overall term, ensuring defendants cannot effectively trade it away at sentencing.
""Access brokers don't just hack one victim — they industrialize the breach, selling entry points to whoever pays. Dragomir's dozens of downstream U.S. victims are the real cost of that model.""
Extradition as Enforcement Signal
Romania has historically been a fertile ground for cybercriminal operations, and while Romanian law enforcement has cooperated with U.S. authorities on numerous high-profile cases, extradition remains a powerful — and relatively rare — escalation. Dragomir's transfer to U.S. jurisdiction signals that the Department of Justice is willing to invest the diplomatic and legal capital required to prosecute foreign nationals in American courts when the victims are American institutions. For the broader community of Eastern European threat actors who assume geographic distance offers meaningful protection, cases like Dragomir's are a direct refutation of that assumption. The FBI and DOJ's sustained investment in international partnerships — particularly through frameworks like the Budapest Convention on Cybercrime — is compressing the operational safety margins that hackers once relied upon.
Dragomir's sentencing lands at a moment when access brokerage has become a primary driver of ransomware economics, critical infrastructure attacks, and government network compromises across the United States. The 56-month term is unlikely to deter the most sophisticated actors, but the extradition precedent it reinforces — that Romanian citizenship is not a shield from U.S. federal prosecution — adds genuine legal risk to a criminal model that has operated with relative impunity for years. As the DOJ continues to prioritize cybercrime extraditions, the geography of consequence is shrinking.
Editorial Note
BleepingComputer is a reputable cybersecurity news outlet with strong track record for accurate reporting on hacking cases and federal prosecutions. The specific claim (Romanian national, 56-month sentence, Oregon govt network, multiple U.S. victims) follows typical patterns of DOJ cybercrime prosecutions that are publicly documented. The plausibility is high as Romanian nationals have been involved in documented U.S. infrastructure breaches, though the exact case would require verification against official DOJ press releases or court records.
Claim Tracker
AI-assessed
Standard biographical detail in federal sentencing reports
Specific sentencing details are typically public court records
Core charge in the case; part of public court filing
Extradition details are part of public legal proceedings
Article is truncated mid-sentence; full scope of victims and charges not detailed in provided text
Ask AI about this story
// discussion
sign in to join the discussion