Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
▣ Breach LATVIA-CSDD-1 2026-09-20

Latvia's CSDD: Web Application Breach Exposing 1.2 Million People

"Latvia's Road Traffic Safety Directorate (CSDD) has confirmed a data breach affecting roughly 1.2 million individuals and about 200,000 legal entities, drawn from 18 years of payment records. On 18 September 2026, a…"

Latvia's Road Traffic Safety Directorate (CSDD) has confirmed a data breach affecting roughly 1.2 million individuals and about 200,000 legal entities, drawn from 18 years of payment records. On 18 September 2026, a commission convened by the Ministry of Transport published its findings: the intrusion was enabled by a vulnerability in a CSDD-operated web application, compounded by inadequate security testing, insufficient network protection, an absence of multi-factor authentication, and flaws in software development practice. With a national population of roughly 1.8 million, the incident touches an estimated two-thirds of Latvian residents and ranks, per Latvian Public Media and Bytes Europe, as the second-largest data breach in the country's history.

Every account below comes from regional and security press rather than a published regulator filing or CERT advisory, so figures and dates are attributed accordingly.

What Happened

The sources agree on the shape of the intrusion but differ slightly on its timing. CERT.LV deputy head Varis Teivāns told journalists (via Baltic News Network) that the incident occurred during the night of Saturday 8 August. Bytes Europe, citing Latvian Television's De Facto, places the entry overnight from 7 to 8 August. Cybernews describes it as happening "on August 8th or 9th." The practical read: the attacker was inside over the weekend of 8 to 9 August.

The disclosure timeline is where the case turns from an intrusion into a governance failure. Teivāns said CSDD did not notify CERT.LV until the evening of Monday 10 August, and that CERT.LV had no telemetry on the affected infrastructure at all because CSDD had declined to use CERT.LV's services, justifying this on the basis of its own in-house capability. "Early detection from the state's perspective was not possible," he said. Once CERT.LV specialists were engaged, the scale began to emerge on the evening of 11 August and the morning of 12 August, per Bytes Europe.

CSDD went public on 13 August with an initial statement to LETA describing a "complex targeted cyberattack" and partial access to its information system. The full 1.2 million figure was not disclosed until 18 August, when board members and the head of IT attended an emergency government meeting. Individual citizens could not check their own exposure until 27 August, according to Cybernews.

De Facto reported that CSDD failed to notify the State Data Inspectorate (DVI) within the statutory 72-hour window, and that police opened a preliminary review on their own initiative before escalating to criminal proceedings over unauthorised access. The DVI is deciding whether to open administrative offence proceedings. LSM's assessment was blunt: the pattern suggests CSDD initially hoped to keep the incident quiet. Cybernews reports that the CSDD board and supervisory council subsequently resigned.

Tet, the IT infrastructure provider working under a reported 9 million euro contract with CSDD, told Bytes Europe it learned unofficially of a possible attack on 10 August when directorate staff reported connection problems, and received an official letter only that Friday, nearly a week after the intrusion. Tet's internal review pointed to an application managed by CSDD itself, outside Tet's security remit, and the company noted that traffic-volume monitoring alone does not flag a cyberattack. Responsibility for the stored data rests with CSDD, per De Facto.

What Was Taken

Reporting converges on 1.2 million individuals and approximately 200,000 legal entities, sourced from historical payment receipts for CSDD services going back roughly 18 years. CSDD told LETA that anyone who has paid for a CSDD service since 2008 may be affected.

Confirmed exposed fields, per CSDD's own statement to LETA and corroborated by BB.LV and Cybernews:

CSDD explicitly stated that customer phone numbers, email addresses, banking data, and e-CSDD access credentials were not affected. The directorate also cautioned that it was still analysing which of the exposed data categories remain current, since much of an 18-year archive is stale.

On downstream exposure, CERT.LV said on 21 August that it had found no confirmation the stolen data had been published or offered for sale, and had identified no fraud cases directly traceable to the leak. That was a point-in-time assessment, not an all-clear.

Why It Matters

Three things make this brief worth more than its record count.

First, the data is durable. A Latvian personal identity code does not rotate. Neither does a name, and a vehicle plate changes rarely. CERT.LV was careful to note that a personal code alone does not grant access to e-services: Smart-ID and eParaksts mobile authorisation still require the holder to approve the prompt on their own device. But that only holds if the holder declines unexpected prompts, which is exactly the behaviour that unsolicited-push fatigue erodes. CERT.LV advised that eParaksts users can substitute a random seven-digit user number for their personal code as an additional layer.

Second, the fraud cycle started before the forensics finished. On Thursday 20 August, criminals sent phishing emails impersonating CSDD and offering to check whether a recipient's data was in the leak, per CERT.LV via BB.LV. Real payment amounts, real dates, and a real plate number give a social engineer enough specificity to defeat the usual "does this look legitimate" heuristic. One victim interviewed by Cybernews described the exposed set as "all the addresses, my car plate numbers, personal code, some payment confirmations."

Third, attribution remains open, and the state-actor hypothesis is live. Baltic News Network quotes Prime Minister Andris Kulbergs saying he could not rule out that the attack was carried out by another state, with no specific attacker identified. CERT.LV said on 21 August that it was working several hypotheses including foreign state support, without confirmation. De Facto reported that the same actor very likely made unsuccessful attempts against other Latvian state systems, inferred from method and timing. Treat state involvement as an unresolved line of inquiry, not a finding.

The Attack Technique

Initial access came through a vulnerability in the CSDD-operated web application at med.csdd.lv, according to the Ministry of Transport commission report summarised by OGRES ZIŅAS. LSM and Bytes Europe describe the same entry point as the "Medical" platform, a portal used by roughly 200 doctors to submit driver medical certificates.

That is the structural lesson. A low-traffic, narrow-audience portal serving a few hundred clinicians became the pivot into records covering two-thirds of the population. The commission's stated failures map directly onto how that pivot succeeded:

No specific CVE, exploit class, or malware family has been published. The commission report is an internal assessment; assigning individual responsibility was explicitly left to law enforcement.

What Organizations Should Do

  1. Inventory your low-traffic, high-privilege applications. Enumerate every internet-facing app that serves a small specialist audience but queries production data stores. Those are the med.csdd.lv equivalents in your own estate, and they are systematically under-tested precisely because nobody complains about them.
  2. Segment until a portal compromise is a dead end. A medical certificate submission tool has no legitimate need to reach 18 years of payment history. Enforce that at the network and data layer, then test the assumption with an assumed-breach exercise rather than a questionnaire.
  3. Make MFA non-negotiable for every application, including the small ones. Exception lists are where the exceptions get exploited. Where identity federation exists nationally or corporately, route the niche portals through it instead of letting them keep bespoke authentication.
  4. Rehearse the 72-hour clock. CSDD reportedly missed the statutory GDPR notification deadline to its DVI and notified the national CERT two days late. Pre-write the notification templates, name the accountable decision-maker, and drill the weekend scenario specifically, since this incident began on a Saturday night.
  5. Do not decline national CERT visibility on the strength of your own capability. CERT.LV said it was blind to the infrastructure by CSDD's own choice. If you opt out of external telemetry, you own detection entirely, and you should be able to prove you can do it.
  6. Write the outsourcing seam into the contract. Tet monitored traffic but was not responsible for the application's code or security, and traffic volume alone did not indicate an attack. Map, in writing, exactly who tests which application, who monitors which signal, and who is called first. Unclaimed ground between client and provider is where this breach lived.
  7. Prepare customer-facing fraud comms before you need them. Impersonation phishing referencing this breach was circulating within a week. Publish a single authoritative self-check channel early, state plainly what you will never send, and reinforce that authentication prompts arriving unrequested must be refused.

Sources: How did data on 1.2 million people leak from CSDD? Investigation re... | Data of 1.2 million people leaked in CSDD cyberattack in Latvia – i... | Hackers Breached CSDD System: What Data of Latvian Residents Could... | Latvian CSDD was late to report cyber attack | Huge Latvia data breach exposes 1.2M citizens' data Cybernews | What is happening with the CSDD data leak: Cert.lv reported on the... | Latvia’s CSDD reported cyberattack with delay - Bytes Europe | CSDD: Kiberuzbrukumā nav iegūti klientu telefona numuri, e-pasta ad...