Thursday, 20 August 2026
Rīga TV

World and Latvian news in one place

LatviaPublished: 20 August 2026 at 15:01

CSDD cyberattack exposes data of 1.2 million people, board resigns

A cyberattack on Latvia's Road Traffic Safety Directorate (CSDD) exposed data of roughly 1.2 million residents and 200,000 companies, gathered from payment records dating back to 2008. Both the CSDD board and council have resigned.

Foto: Delfi

A cyberattack on the Road Traffic Safety Directorate (CSDD) has exposed personal data belonging to approximately 1.2 million individuals and 200,000 legal entities. The breach was disclosed on August 18 by Varis Teivāns, deputy head of Latvia's cybersecurity incident response institution Cert.lv. Between August 8 and 10, the attacker extracted information from CSDD payment receipts covering a period dating back to 2008 — nearly 18 years of records.

According to Teivāns, the attack exploited a vulnerability in a CSDD system accessible online that had not been fixed and, based on current information, had not previously been detected. The investigation found that several Cabinet of Ministers requirements had not been followed — for instance, Class A systems are required to undergo penetration testing and use multi-factor authentication. Although the breach occurred on a Saturday night, CSDD only reported it to Cert.lv on Monday evening. CSDD had also previously opted out of Cert.lv services, meaning the oversight body had no visibility into this system.

What data was stolen

The attacker obtained personal identity codes or company registration numbers, names or company titles, payment amounts and dates, vehicle registration plate numbers, and addresses listed at the time in documents such as vehicle registration certificates. CSDD stated that phone numbers and email addresses were not affected.

Residents urged to stay alert

Experts are advising people not to approve Smart-ID or eParaksts mobile authentication requests they did not initiate themselves, and to carefully verify texts, emails, or calls that appear to come from CSDD or other institutions. Anyone using their personal identity code as their eParaksts mobile username is advised to switch to a randomly generated seven-digit combination instead.

The IT infrastructure for CSDD's systems is managed by the company Tet, which signed a contract with CSDD in 2022 worth nearly €9 million, involving subcontractors as well. Tet has confirmed it has launched an investigation into the incident.

Following the attack, President Edgars Rinkēvičs said CSDD's leadership could not continue in their roles, calling the breach a serious threat to national security. The prime minister echoed this stance. Transport Minister Rihards Kozlovskis ordered a review of the board and council's responsibility, and after meeting with the minister, both the council and the board announced their resignations.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category