SYS::ONLINE
Wasteland.
Briefs2196
Issues24
SinceFeb 2026
LIVE
▣ Breach CSDD-LATVIA-GOVERN 2026-08-23

Latvia's CSDD: Unattributed Intrusion Exposes 1.2 Million Citizens

"Latvia's Road Traffic Safety Directorate (CSDD), the state agency that runs vehicle registration and driver licensing under the Transport Ministry, was breached between 8 and 10 August 2026. In a joint statement with…"

Latvia's Road Traffic Safety Directorate (CSDD), the state agency that runs vehicle registration and driver licensing under the Transport Ministry, was breached between 8 and 10 August 2026. In a joint statement with national CERT.LV, CSDD confirmed that an attacker extracted data from payment receipts going back to 2008, affecting 1.2 million individuals and 200,000 legal entities. Latvia's total population is just over 1.8 million, meaning roughly two-thirds of the country is in the stolen set. Two weeks on, the incident has escalated from a technical failure into a national accountability crisis: the CSDD board chairman has said he is prepared to resign, and Prime Minister Andris Kulbergs has publicly raised the possibility of a conflict of interest inside the agency's own security function. No threat actor has been identified, and the parties involved openly disagree about who failed.

What Happened

CERT.LV deputy head Varis Teivāns told journalists the intrusion occurred during the night of Saturday 8 August. CSDD did not notify CERT.LV until the evening of Monday 10 August, a delay Teivāns said was partly explained by the weekend timing. Critically, he added that CERT.LV had no visibility into the affected infrastructure at all, because CSDD had opted not to use CERT.LV's services, a decision Teivāns said was justified internally on the basis of CSDD's own capabilities. "Early detection from the state's perspective was not possible," he said.

The public disclosure cadence drew heavy criticism. Per LSM, it took four days to inform the public and another four days for the full scale of the breach to be admitted. CERT.LV's advisory was first published on 13 August and updated with the completed data analysis on 18 August.

Accounts of who was responsible for monitoring diverge sharply, and this is the central unresolved dispute in the case:

Note that both narratives converge on a departed or dual-hatted individual inside the security function, but no source directly identifies them as the same person. That link is not established and should not be assumed.

Aksenoks initially signalled he would not resign. LSM reports that an intervention by President Edgars Rinkēvičs, who hinted that heads should roll, changed his position; he now says he will step down once the investigation concludes. He has also rejected the prime minister's characterisation that CSDD is "trying to cover our tracks and cover our backsides" rather than fixing the problem, and suggested not all reporting on the incident has been accurate.

The Record reported that CSDD faced a further attempted cyberattack over the following weekend, which it blocked using security improvements introduced after the initial breach.

What Was Taken

CERT.LV's advisory and CSDD's statement list the affected data categories consistently across all reporting:

Volume figures are unusually consistent here. CERT.LV, BNN, BB.LV and LSM all state 1.2 million natural persons and 200,000 legal entities; The Record phrases it as "more than 1.2 million people and 200,000 businesses and other legal entities." The historical depth is described as either "back to 2008" or "the past 18 years," which are the same window.

CSDD states that customer phone numbers and email addresses were not affected, that usernames and passwords were not compromised, and that address information is incomplete in some records. Day to day operations were not disrupted, and both online and in-person services stayed available. As a precaution, CSDD restricted access to the public service allowing lookups of a vehicle's make and model by licence plate.

The Latvian personas kods is a durable national identifier used across banking, healthcare and government services. Paired with a name, a historical address and a licence plate, it constitutes a high quality identity dossier that does not expire the way a password does. CERT.LV and CSDD have both warned that the data enables social engineering and fraud.

Why It Matters

This incident is less interesting as an intrusion than as a governance failure, and that is exactly what makes it broadly applicable.

Outsourced monitoring is not outsourced accountability. CSDD paid a vendor monthly for continuous monitoring including firewall and incident detection, and by the chairman's own account received no alert for an intrusion that ran across a weekend. Whether the detection gap sits with the vendor, with the scope of the contract, or with what CSDD instrumented for the vendor to see is precisely what the investigation must determine. Defenders should read the finger-pointing as a warning about contracts that transfer the activity of monitoring without ever defining the outcome of detection.

Free national CERT visibility was on the table and did not get deployed. Both accounts agree that CERT.LV sensor coverage was discussed and never implemented. They disagree only on whether that was a decision or an administrative dead end. Either failure mode is common: a security offer that lives entirely in one person's inbox and never reaches a governance body is functionally a rejected offer.

Conflict of interest inside the security function is an underweighted risk. The prime minister's allegation, if verified, describes a structure where the person assessing supplier security also had an economic relationship with that supplier. That is a control failure independent of whether anyone acted maliciously, and it is a question worth asking of any small agency where one specialist owns both vendor management and security assurance.

Weekend detection latency remains a real gap. The intrusion occurred overnight Saturday and the national CERT learned of it Monday evening. Attackers pick that window deliberately.

Notification at national scale is legally constrained. With 1.2 million affected, CSDD says individual notification is not feasible and, per LSM, Latvian law bars it from confirming an individual's exposure by phone or email. Citizens must submit an electronically signed request with their name and personal ID code. Over a thousand people had already contacted the agency by 21 August. Analysis is ongoing to determine how much of the 2008 onward data remains current.

The Attack Technique

Attribution and technique detail remain thin, and no source claims a named actor, malware family or CVE.

CERT.LV has indicated that a vulnerability in an internet-facing CSDD system was used for the attack, and that several mandatory cybersecurity requirements were not met. The specific vulnerability has not been disclosed publicly.

On authentication, Kulbergs stated that ordinary login and password credentials were used where two factor authentication would have been the stronger control. This is the prime minister's characterisation and has not been separately confirmed by CERT.LV or CSDD.

On attribution, Kulbergs told journalists on 18 August that he could not rule out that the attack was carried out by another state, while explicitly framing this as speculation because the perpetrator is unknown. Both BNN and BB.LV report the comment with that caveat attached. Treat it as an open hypothesis, not an assessment.

On scope of access, CERT.LV's advisory states the attacker obtained data contained in payment receipts across 8 to 10 August inclusive. CSDD has described the access to its IT systems as partial. Aksenoks says the intrusion was stopped within a couple of hours of detection by CSDD's internal team, which is compatible with a multi-day exfiltration window only if detection came late in that window. The published record does not reconcile these two timelines, and CSDD's ongoing investigation has not closed the gap.

What Organizations Should Do

  1. Audit the gap between monitoring contracts and detection outcomes. For every managed detection or infrastructure contract, confirm in writing what telemetry the vendor actually receives, what triggers an alert, what the notification SLA is out of hours, and who verifies that alerting still works. Run a live test rather than trusting the statement of work.
  2. Close the informal-channel gap for security offers and findings. Route any proposal from a national CERT, regulator or partner through a documented intake that reaches the board or equivalent governance body. A security decision that exists only as an email thread between two specialists is a decision nobody made and nobody can defend.
  3. Check for dual-hat conflicts in vendor assurance. Identify anyone who both owns security assessment of a supplier and has an employment, contracting or ownership relationship with that supplier. Separate the roles, or require a documented independent review of that supplier.
  4. Enforce phishing-resistant multi-factor authentication on every internet-facing administrative and remote access path. Password-only access to systems holding national identifier data is the control failure most cited in this case.
  5. Treat historical transaction archives as live sensitive data. CSDD's exposure spans 18 years of payment receipts. Inventory what old records your internet-facing applications can still reach, and apply retention limits, segmentation and field-level protection to identifiers such as national ID and plate numbers.
  6. Rehearse mass-notification under legal constraints. Determine in advance how you would tell millions of people whether they are affected, what your regulator permits over email and phone, and what self-service the affected can use. CSDD is pointing citizens to their own payment history in the e-CSDD portal and app; have that equivalent ready before you need it.
  7. Assume follow-on fraud and message accordingly. CERT.LV and CSDD are advising the public to scrutinise unexpected messages appearing to come from the agency, check language and spelling quality, avoid links, and verify via official channels. Publish a single authoritative status page and never send links in breach communications.

Sources: “Worked on Both Sides”: Prime Minister Reveals New Details of the C... | Latvian officials resign after cyberattack exposes data on ... | Data of 1.2 million people leaked in CSDD cyberattack in Latvia – i... | Personal data of more than 1 million residents of Latvia stolen fro... | CSDD boss ready to quit over massive database leak | Search for accountability begins after massive data breach in Latvi... | Public demand answers about CSDD hack but are unlikely to get them... | CSDD saskāries ar kiberdrošības incidentu CERT.LV