Major Data Breach at Latvia's Road Traffic Agency

Latvia's Road Traffic Safety Directorate, known as CSDD, has confirmed that hackers stole personal data connected to roughly two-thirds of the country's population in a significant cyberattack. The breach, first reported on August 18, affected records belonging to more than 1.2 million people and 200,000 businesses and other legal entities. Latvia's population is just over 1.8 million.

According to CSDD, the attackers accessed data from payment receipts dating back to 2008. The stolen information includes personal identification numbers or company registration numbers, vehicle license plate numbers, payment amounts and dates, and addresses listed on vehicle registration certificates.

In a statement, Māris Puriņš, Head of CSDD's IT Department, confirmed that customer contact details such as telephone numbers and email addresses were not compromised. He added that address information was not complete in all cases.

"The CSDD is continuing its investigation into the cyberattack; we have restricted the ability of unauthorised users to process vehicle information based on their national registration number, thereby obtaining details of the make and model, and we are continuing to cooperate with the relevant authorities, providing all the information at the CSDD's disposal to identify the perpetrator," Puriņš said.

CSDD said its day-to-day operations had not been disrupted and that both online and in-person services remained available. The agency also restricted access to a service that allows users to look up vehicle information by license plate number.

The agency said it faced another attempted cyberattack over the weekend but blocked it following security improvements introduced after the initial breach.

Expert Warnings and Response

Varis Teivāns, deputy head of Cert.lv, Latvia's computer emergency response team, explained that the most significant risk posed by the leaked data is its potential use in future social engineering and fraud campaigns.

"When fraudsters have a person's name, personal identification number, car registration number, address or details of a previous payment, they can create significantly more credible and personalised fraudulent text messages, emails, or calls," Teivāns said, as reported by LSM.

CERT.LV warned that criminals could use the stolen information in social engineering and fraud schemes. CSDD informed the State Data Inspectorate of the cyberattack and retained all information at its disposal for a comprehensive assessment.

Political Fallout and Resignations

The attack has triggered political consequences. Latvia's President Edgars Rinkevics said the attack posed "a significant threat to national security" and argued that CSDD's leadership should step down. Latvian member of Parliament Andris Kulbergs also called for CSDD's management and supervisory board to resign.

On Wednesday morning, CSDD's supervisory board submitted its resignation. CSDD chief Aivars Aksenoks said he was preparing to leave once he had helped complete the investigation and address the consequences of the attack.

Aksenoks suggested that responsibility for the breach may not lie with CSDD alone, pointing to Latvian telecom and technology company Tet, which provides some of CSDD's IT infrastructure and security monitoring. CSDD has a five-year contract with Tet covering IT infrastructure maintenance and monitoring, including some firewall and incident-monitoring functions.

According to Aksenoks, Tet did not detect the intrusion or alert the agency, and CSDD employees discovered the attack themselves and stopped it within several hours. Tet chairman Uldis Tatarcuks said investigators first need to determine how and when the attackers gained access, which systems were compromised, and where security measures failed.

The state police have opened criminal proceedings into the cyberattack.

Context: Prior Cyberattack on State-Owned Company

The CSDD breach follows a ransomware attack in June on state-owned forestry company LVM. That attack disrupted LVM's mapping platform, hunting application, and systems used to exchange information with contractors and customers. Officials said the election system was not affected by the LVM attack because it was developed separately and its source code was not stored on LVM's network.

Ongoing Investigation

CSDD continues to investigate the attack and work with relevant authorities to identify the perpetrators. CERT.LV told LSM that hackers exploited a vulnerability in a CSDD system exposed to the internet and that several mandatory cybersecurity requirements had not been met, though this information has not been independently verified by other sources in this report.