Investigation identifies causes of CSDD data breach
A Transport Ministry commission has completed its evaluation of a cyberincident at Latvia's Road Traffic Safety Directorate (CSDD), concluding that several cybersecurity management shortcomings contributed to the data leak.
/nginx/o/2026/09/18/17925152t1h0b44.jpg)
A commission set up by Latvia's Transport Ministry has concluded its review of a cyberincident at the Road Traffic Safety Directorate (CSDD) that resulted in a data breach. The evaluation found that the leak was caused by a combination of shortcomings in the agency's cybersecurity management.
Shortcomings identified
The commission pointed to four main problem areas. First, security checks within CSDD's systems were found to have incomplete coverage, meaning they did not extend across all necessary infrastructure. Second, the review identified insufficient network protection, which made unauthorized access to data easier. Third, the agency lacked multi-factor authentication, a security measure widely regarded as a baseline safeguard against unauthorized access even when passwords are compromised. Fourth, the commission found deficiencies in the software development processes used by the agency.
What happens next
The evaluation follows an earlier cyberincident that compromised data held by CSDD. The Transport Ministry says the identified shortcomings need to be addressed in order to strengthen the agency's cybersecurity and prevent similar situations from recurring. The source report does not provide further details on the timeline or specific measures planned to fix the identified issues.


