Thursday, 20 August 2026
Rīga TV

World and Latvian news in one place

LatviaPublished: 20 August 2026 at 12:59

CSDD reveals which personal data was exposed in cyberattack — risk dates back to 2008

Latvia's Road Traffic Safety Directorate (CSDD) says an August 10 cyberattack gave a third party unauthorized access to client payment receipt data. Anyone who has paid for CSDD services since 2008 may be affected.

Foto: Jauns.lv

The Road Traffic Safety Directorate (CSDD) has provided further details on a sophisticated cyberattack against its IT systems on August 10, 2026, during which an unauthorized third party gained access to client data contained in payment receipts stored in its information systems.

What data was affected

CSDD clarified that only personal data included in payment receipts was compromised: the client's name and surname or company name, personal identity number or company registration number, payment amount and date, the vehicle's state registration plate, and the address registered at the time the service was received.

The agency stressed that other client data — phone numbers, email addresses, banking details and e-CSDD login credentials — were not affected. Authentication for CSDD e-services currently requires secure methods such as eID, eParaksts mobile, eID Scan, Smart-ID or internet banking.

Risk dating back to 2008

CSDD warned that data belonging to anyone who has made even a single payment for its services since 2008 could potentially have been exposed. Clients can log into the e.csdd.lv portal, go to "Other payments" – "payment history," to view their own payment records and the personal data they contain. The agency noted it is still assessing how current and relevant the exposed data actually is.

CSDD urged residents to stay vigilant and follow cybersecurity experts' public advice, warning that a stolen personal identity number could theoretically be used to attempt unauthorized authentication requests, for instance via Smart-ID.

Ongoing investigation

CSDD is cooperating with the State Police, providing all available information to help identify and prosecute those responsible for the attack. The agency has also preserved all data related to the incident for submission to the Data State Inspectorate for a full assessment. In line with Article 34 of the General Data Protection Regulation, CSDD has published a formal notice about the data breach on its website.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category