Wednesday, 19 August 2026
Rīga TV

World and Latvian news in one place

RegionsPublished: 19 August 2026 at 08:00

CSDD cyberattack exposes personal data of 1.2 million people, PM does not rule out hostile state involvement

A cyberattack on Latvia's road traffic safety agency CSDD leaked data belonging to roughly 1.2 million people and companies, with Prime Minister Andris Kulbergs saying a foreign state operation cannot be excluded.

Foto: OgreNet

Latvia's Road Traffic Safety Directorate (CSDD) suffered a cyberattack on the night of August 7-8 that resulted in the leak of data belonging to approximately 1.2 million individuals and businesses. The compromised records include personal identity numbers or company registration numbers, names, payment amounts and dates, vehicle registration plates, and addresses registered at the time services were received. No leak of bank account details or other data posing immediate financial risk has been identified.

CSDD and the national cybersecurity institution Cert.lv are urging the public to be cautious of messages, emails or calls appearing to come from CSDD or other institutions, to watch for language and spelling errors, and to avoid clicking links in such messages. Citizens are advised to verify information via the official site e.csdd.lv or the CSDD mobile app. Particular caution is urged regarding unsolicited authentication requests in tools such as eParaksts or Smart-ID, where usernames are often personal identity numbers.

Delayed response and security gaps

Cert.lv was only notified of the incident on the evening of August 10, since CSDD had earlier opted out of Cert.lv's services, making early detection impossible. The investigation found that CSDD failed to meet Cabinet of Ministers requirements for Class A systems, including regular penetration testing and multi-factor authentication.

Prime Minister Andris Kulbergs said he only learned of the attack a week later, from the head of the Constitution Protection Bureau, and stated the situation is more serious than previously disclosed. He compared the case to a recent cyberattack on state forestry company Latvijas valsts meži, saying both incidents reflected irresponsible attitudes toward cybersecurity rather than a lack of funding or specialists.

Because the attacker has not identified itself and the stolen data has not surfaced publicly, Kulbergs said a hybrid operation by a hostile foreign state cannot be ruled out as an attack on critical infrastructure. The Crisis Management Centre, together with Cert.lv and CSDD, will lead the response through a newly formed working group, and Cert.lv sensors will become mandatory for all critical infrastructure. The Defence Ministry has been tasked with establishing a 24-hour national cybersecurity centre.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category