CSDD launches dedicated webpage on cyberattack, as blame debate with Tet continues
Latvia's Road Traffic Safety Directorate (CSDD) has created a single web section gathering all information about the recent cyberattack on its systems, while responsibility for the breach is still being debated with tech company Tet.

The Road Traffic Safety Directorate (CSDD) has added a new section to its official website titled "Current information on the cybersecurity incident," consolidating everything the public needs to know about the recent hack of its information system. The section covers details of the attack itself, which data were affected, how clients can find out if their information was compromised, and advice on avoiding scammers. CSDD says the page will be continuously updated.
Who is responsible: CSDD or Tet?
Following a meeting with the board of telecom company Tet and asset manager Possessor, Economy Minister Viktors Valainis said the breach occurred through CSDD's own "med.csdd.lv" application, whose cybersecurity was not covered by Tet's contract. Under its agreement, Tet manages CSDD's network infrastructure and connections and monitors data traffic, but is not responsible for securing applications developed in-house by CSDD. Tet also lacked access to that application's log files, which prevented it from detecting the intrusion.
Valainis stressed that state institutions must strengthen their readiness for cyber threats and that transition periods for implementing cybersecurity requirements should be reconsidered. Tet's CEO Uldis Tatarčuks added that opportunities to improve cybersecurity had existed earlier, including cooperation with Cert.lv and introducing two-factor authentication, noting that protections required by law should have been in place three years ago.
Prime Minister Andris Kulbergs said the intrusion occurred through the "Medical" platform used by roughly 200 doctors, which could be accessed with just a username and password, without multi-factor authentication.
Background
The early-August attack exposed personal data of around 1.2 million individuals and roughly 200,000 legal entities, drawn from payments made to the directorate over the past 18 years. CSDD's board and council have already resigned, the transport minister has ordered an expedited internal investigation, and the President has asked the Prosecutor General's Office to review officials' conduct.


/nginx/o/2026/08/21/17869747t1ha8d8.jpg)