Friday, 28 August 2026
Rīga TV

World and Latvian news in one place

LatviaPublished: 28 August 2026 at 04:16

CSDD clients shocked by scale of stolen data after cyberattack — ID numbers, addresses, car plates exposed

After Latvia's Road Traffic Safety Directorate (CSDD) let clients check what data was stolen in a recent cyberattack, people have been sharing on social media how exposed their personal codes, addresses and vehicle details are. CSDD has refused free license plate changes, while an expert warns compensation claims will be hard to win in court.

Foto: Jauns.lv

After the Road Traffic Safety Directorate (CSDD) enabled clients to check exactly what personal data hackers accessed during a recent large-scale cyberattack, Latvians have flooded social media with reactions to what they found.

Users report the lookup tool reveals full names, national ID (personal) codes, both declared and actual home addresses, vehicle registration plates, and even payment dates and amounts. Some noted that data tied to relatives' cars also appeared if they had paid a bill on someone else's behalf. Several commenters argued that given roughly 1.2 million people's data was stolen, virtually every CSDD client has effectively been affected.

Compensation prospects unclear

Security expert and economist Krišjānis Feldmans, speaking on the TV24 programme "Preses klubs," said the State Data Inspectorate has confirmed people can sue for compensation, but must prove a direct causal link between the data leak and actual damages suffered. He predicted such lawsuits would likely fail in court due to this evidentiary burden. Earlier, Inspectorate director Jekaterina Macuka said compensation is due if the leak caused harm, and that with 99.9% certainty, anyone who made a CSDD payment in the past decade had their data exposed.

CSDD has stated there is no legal basis for free vehicle registration plate replacement, despite Prime Minister Andris Kulbergs suggesting affected residents should be allowed to change plates at no cost. The agency said it must follow existing regulations and awaits a Cabinet of Ministers decision on the matter.

Aftermath of the breach

The cyberattack, which occurred on the night of August 8, exposed data belonging to 1.2 million individuals and roughly 200,000 legal entities, drawn from payment records spanning the past 18 years. Compromised data included names, personal codes, payment amounts and dates, vehicle plates, and the address on file at the time of service — but phone numbers, emails, banking details and e-CSDD login credentials were not affected.

Both CSDD's supervisory council and board resigned following the breach. Transport Minister Rihards Kozlovskis has ordered an expedited internal investigation, including a review of CSDD's cybersecurity contract with Tet, while President Edgars Rinkēvičs has asked the Prosecutor General to examine the actions of CSDD officials regarding data security.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category