Thursday, 3 September 2026
Rīga TV

World and Latvian news in one place

LatviaPublished: 3 September 2026 at 20:26

Cert.lv explains how attacker breached Latvian consumer rights agency's system

Latvia's cybersecurity agency Cert.lv detailed how an attacker exploited a public-facing flaw in the Consumer Rights Protection Centre's system to extract contact data of hundreds of people. Officials say no personal ID codes or sensitive data were exposed.

Foto: Latvijas Avīze

Cybersecurity specialist Gints Mālkalnietis of Latvia's incident response institution Cert.lv said Thursday that an attacker breached a system belonging to the Consumer Rights Protection Centre (PTAC) by exploiting a vulnerability in its public-facing component. The internal part of the system and internal user accounts were not affected — the attacker extracted data directly through the flaw from the open internet.

Mālkalnietis explained this was a typical software architecture flaw, the kind that can occur due to coding errors and is not unusual, since bug-free code is essentially impossible. Cert.lv discovered the breach by monitoring publicly available information online, where the attacker had disclosed that PTAC's system had been hacked and files extracted. PTAC's IT security officer was notified late on September 1. No ransom was demanded. The attacker's IP address had not previously been linked to other incidents tracked by Cert.lv, and while its exact origin remains unclear, it is known not to be from Russia or elsewhere in Europe.

What was exposed

PTAC director Zaiga Liepiņa stressed that no personal identification codes or other sensitive personal data are stored in the system. The affected platform, the Remote Statistical Data Extraction System (ASDIS), has allowed businesses to submit reports electronically since 2018. Contact details of 697 business representatives and 34 PTAC officials — names, email addresses and phone numbers — were extracted. Of these, 106 individuals' data is not legally required to be public; the rest is already published in other databases.

Known vulnerabilities, limited funding

Liepiņa acknowledged that PTAC already knew about vulnerabilities in the system and had planned fixes, including a maintenance contract and an audit, but a full rebuild had been held back by insufficient funding, which the agency had repeatedly requested. Total spending on the system to date is under €10,000. ASDIS is classified as a lowest-risk level-C system. It has been offline since the morning of September 2 and will resume once security is confirmed. PTAC plans to hire ethical hackers to test the system and reassess all risks.

Mālkalnietis added that this attack was technically simpler than earlier breaches affecting state forestry company Latvijas valsts meži and the Road Traffic Safety Directorate (CSDD), and the volume of affected data is not comparable. He warned that outdated, unpatched systems can remain exposed online for years.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category