CSDD clarifies which personal data was not stolen in cyberattack
Latvia's Road Traffic Safety Directorate (CSDD) says attackers behind the early-August cyberattack, which affected around 1.2 million individuals and 200,000 legal entities, did not obtain clients' phone numbers, email addresses, bank details or 'e-CSDD' login credentials.

The Road Traffic Safety Directorate (CSDD) has provided further details about the cyberattack that hit the agency in early August, specifying which categories of client data were not accessed. According to CSDD, attackers did not obtain clients' phone numbers, email addresses, banking information, or login credentials for the 'e-CSDD' online services platform.
At the same time, the agency confirmed that the breach did affect data contained in payment receipts issued by CSDD — including a person's or company's name, personal identity number or registration number, payment amount and date, the vehicle's registration plate number, and the address registered at the time the service was received.
Data from payments since 2008 potentially affected
CSDD explained that if a client has made at least one payment for its services since 2008, their data could potentially have been compromised. Clients can check their own data by logging into the 'e.csdd.lv' portal and viewing their payment history under 'Other payments'. The agency added that the exact scope of affected data that remains current is still being analyzed, since not all historical data is still relevant today.
Clients are advised to remain cautious, as personal identity numbers could be used for fraudulent purposes, including attempts to initiate authentication requests through tools such as 'Smart-ID'. Currently, CSDD's e-services can only be accessed using secure authentication methods — 'eID', 'eParaksts mobile', 'eID Scan', 'Smart-ID', or internet banking.
Investigations underway on multiple fronts
The cyberattack, which occurred on the night of August 8, affected data on roughly 1.2 million individuals and 200,000 legal entities, drawn from payments made over the past 18 years. On Wednesday, August 19, both CSDD's supervisory council and management board announced their resignation. Transport Minister Rihards Kozlovskis has ordered an expedited internal service investigation, which will also examine CSDD's contract with 'Tet' for cybersecurity services. President Edgars Rinkēvičs has written to the Prosecutor General requesting a review of CSDD officials' conduct regarding data security. CSDD is cooperating with the State Police and will also submit its information to the Data State Inspectorate.
/nginx/o/2019/11/21/12756310t1h774f.jpg)

