SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach LATVIA-CSDD-GOVERN 2026-08-18

Latvia's CSDD: 1.2 Million Residents' Data Stolen in Targeted Intrusion

"Latvia's Road Traffic Safety Directorate (CSDD) has confirmed that a cyberattack on its IT systems resulted in the theft of personal data belonging to 1.2 million people, a figure disclosed on 18 August by Varis…"

Latvia's Road Traffic Safety Directorate (CSDD) has confirmed that a cyberattack on its IT systems resulted in the theft of personal data belonging to 1.2 million people, a figure disclosed on 18 August by Varis Teivāns, deputy head of the national cyber incident response institution CERT.LV, and echoed in CSDD's own statement the same day. The stolen material consists of historical payment receipts for CSDD services stretching back roughly 18 years, to 2008. Baltic News Network, citing LETA, additionally reports that data on approximately 200,000 legal entities was taken; that entity count appears in only one of the available reports and should be treated as single sourced. For scale, Latvia's total population is under two million, meaning the affected set plausibly covers a majority of the country's adult residents and vehicle owners.

What Happened

CSDD first disclosed on 13 August that it had suffered what it described as a complex, targeted cyberattack over the preceding weekend, during which attackers gained partial access to its information systems and extracted historical payment receipt data. Delfi, TVNET and BB.LV all carried substantively the same CSDD statement via LETA on 13 August, using near identical wording about partial IT system access and unauthorised extraction of receipt records.

The timeline tightened on 18 August. Teivāns told journalists that the incident occurred during the night of Saturday 8 August, but that CSDD did not notify CERT.LV until the evening of Monday 10 August. He attributed the delay in part to the incident falling over a weekend, but made a sharper point about visibility: CERT.LV had no telemetry into the affected infrastructure because CSDD had chosen not to use CERT.LV's services. "This was justified on the basis of CSDD's own capabilities, which meant that early detection from the state's perspective was not possible," Teivāns said, as reported by BNN.

Public disclosure was criticised as thin in the intervening days. Latvian public broadcaster LSM ran a piece on 14 August under the headline "CSDD data hack: public still told few details," reflecting a roughly five day gap between the intrusion and any meaningful accounting of scope.

CSDD says the attack has been halted by its IT team working with CERT.LV, and that security hardening measures have since been implemented. Māris Puriņš, head of CSDD's IT department, stated that CSDD faced a further targeted cyberattack over the following weekend, and that this second attempt was blocked thanks to those improvements. In person and electronic CSDD services were not disrupted at any point.

What Was Taken

CSDD and CERT.LV have published a consistent field list across every source. The stolen payment receipt records contain:

Puriņš stated that customer contact details, specifically telephone numbers and email addresses, were not compromised, and that address information is not present in all of the affected records. That is a meaningful limitation on the dataset, and it is the victim's own claim rather than an independent finding.

On volume, the reporting is broadly consistent rather than conflicting. BB.LV's 18 August headline says "more than 1 million" while its own body text cites 1.2 million, matching CERT.LV. The only figure carried by a single outlet is the ~200,000 legal entities reported by BNN. No source in this set reports a differing count for affected individuals.

The sensitivity here is specific to Latvia's identity model. The personas kods is a durable national identifier used across banking, healthcare, e-government and contract signing. It cannot be rotated the way a password or card number can. Paired with a name, a legal address of record, a plate number and a verifiable payment history, it constitutes a near ideal kit for identity impersonation and pretexting.

Why It Matters

Teivāns has been explicit that the dominant risk is not credential theft but social engineering at national scale. "When fraudsters have a person's name, personal identification number, car registration number, address or details of a payment," they can construct highly personalised messages, emails and phone calls that defeat the usual generic phishing tells. A scam call that opens by correctly citing what you paid CSDD, for which vehicle, and on what date, converts at a rate that untargeted fraud never will.

The 18 year retention window is the second strategic lesson. This was not a live transaction database compromise; it was an archive. The organisation's exposure was defined by data it had kept, not data it was using. Every year of retained receipts multiplied the blast radius of a single intrusion.

Third, the CERT.LV visibility gap is the finding most transferable to other defenders. A state agency opted out of national CERT monitoring on the basis of its own internal capability, and the result was that detection depended entirely on the victim noticing its own breach, over a weekend, with a roughly 48 hour lag before national responders were told. That is a governance failure pattern, not a technology one.

On attribution, restraint is warranted. Prime Minister Andris Kulbergs told journalists he could not rule out that the attack was carried out by another state, but both BB.LV and BNN frame this explicitly as speculation, noting the specific perpetrator remains unidentified. No source in this set names a threat actor, a ransomware brand, or a leak site posting. No extortion demand has been reported. As of publication, this is an unattributed intrusion with a data theft outcome.

The Attack Technique

Details are limited and, in the material available, partly truncated. Teivāns indicated that the cyberattack was made possible by a vulnerability, but the specific flaw, product and CVE are not stated in any of the sources reviewed here. No initial access vector, malware family or exfiltration method has been publicly described.

Two secondary indicators are worth noting for defenders. First, CSDD says it has restricted the ability of unauthorised users to look up vehicle information by state registration number to retrieve make and model details. That control change suggests a public or semi public lookup function was in scope of the attackers' interest, either as an enrichment path or as part of the access chain. Second, the fact that a follow up targeted attack arrived the next weekend and was blocked indicates a persistent adversary probing the same target rather than an opportunistic scan and grab.

Treat anything beyond this as unestablished. Accounts across the Latvian press are consistent on outcome and silent on mechanism.

Official Response and Investigation

The State Data Inspectorate (Datu valsts inspekcija, DVI) received notification from CSDD on Thursday 13 August and, per TVNET citing LETA, will assess the causes of the attack, the volume of personal data affected, and the technical and organisational measures CSDD implemented to prevent or mitigate the incident. DVI said it will then decide whether to open a deeper formal inspection, which is the step that would carry GDPR enforcement weight.

Separately, the State Police opened a departmental review on its own initiative after obtaining additional information about the suspected attack, rather than waiting on a referral.

CSDD says its own investigation continues and that it is providing all information at its disposal to the relevant authorities to identify the perpetrator. Both CSDD and CERT.LV have issued public fraud warnings, advising residents to scrutinise the language quality and spelling of any message purporting to come from CSDD, to check how names and addresses are rendered, not to click links in suspicious messages, and to verify communications through the e.csdd.lv portal or the official CSDD mobile app.

What Organizations Should Do

  1. Audit retention on transactional archives. Ask what the oldest record in every customer facing payment or receipt store is, and why it still exists. An 18 year archive of identity linked receipts is a liability with no operational return. Define and enforce deletion schedules, and separate live transaction stores from historical ones with different access controls.

  2. Do not opt out of national CERT or sector SOC telemetry. If your organisation has declined external monitoring on the grounds of internal capability, revisit that decision at board level. Independent visibility is what catches the incident your own team misses at 02:00 on a Saturday.

  3. Fix weekend and holiday escalation. A 48 hour gap between compromise and notifying national responders is a process defect. Test out of hours escalation paths with an unannounced drill, and set an explicit internal SLA for notifying external authorities that does not depend on a business day starting.

  4. Rate limit and authenticate public lookup endpoints. CSDD restricted plate to make and model queries after the fact. Inventory every unauthenticated enrichment endpoint you expose, apply throttling and abuse detection, and log queries by source in a way you can retrospectively analyse.

  5. Pre build the fraud response, not just the breach response. Where the exposed data is a non rotatable national identifier, notification alone does nothing protective. Prepare authenticated communication channels customers can verify independently, publish a plain statement of what you will never ask for by phone or SMS, and brief your own call centre before the impersonation wave starts.

  6. Assume a second wave. CSDD was targeted again within a week. After any confirmed intrusion, keep elevated monitoring and blocking posture in place for weeks, not days, and prioritise patching and hardening on the same attack surface that was already probed.

Sources: Personal data of more than 1 million residents of Latvia stolen fro... | Data of 1.2 million people leaked in CSDD cyberattack in Latvia – i... | Hackers Breached CSDD System: What Data of Latvian Residents Could... | CSDD data hack: public still told few details / Article | DVI vērtēs CSDD kiberuzbrukumā skarto personas datu apjomu | Data of 1.2 million people breached in recent CSDD cyberattack | In Latvia, a cyberattack resulted in the leak of data on 1.2 ... | CSDD cietis kiberuzbrukumā