Friday, 18 September 2026
Rīga TV

World and Latvian news in one place

LatviaPublished: 18 September 2026 at 13:44

Investigation finds multiple cybersecurity failures behind CSDD data leak

A Transport Ministry commission has concluded that a series of technical and organizational shortcomings enabled the CSDD cyberattack that exposed data of roughly 1.2 million people. The report has been forwarded to law enforcement.

Foto: BNN

A commission set up by Latvia's Transport Ministry has completed its review of the cyberattack on the Road Traffic Safety Directorate (CSDD), concluding that the data leak resulted from multiple weaknesses in cybersecurity management. Transport Minister Rihards Kozlovskis said the assessment revealed several errors and, at times, a formal approach that failed to fully prevent the attack.

Vulnerability opened the door

The commission found that the attacker gained initial access to CSDD's information systems through a vulnerability in the "med.csdd.lv" web application maintained by the agency. Several technical and organizational gaps delayed fixing this vulnerability earlier, including incomplete security-check coverage, insufficient network protection, lack of multi-factor authentication, and software development shortcomings. The review also found that historical personal data had been stored for an excessively long period, an issue now to be assessed by the State Data Inspectorate.

Controls existed but often failed in practice

Although a cybersecurity control system was in place at CSDD, it repeatedly failed to achieve its purpose in practice. The commission cited insufficient specialist capacity, a limited scope of security testing and audits, and incomplete documentation. Once inside the system, the attacker was able to extract data over an extended period and on a large scale, since there were no adequate mechanisms to monitor request volumes or detect anomalies. The commission noted that a professional security monitoring provider would normally be expected to identify and limit such unusual, prolonged data activity.

The commission also noted that after detecting the incident, CSDD fulfilled its legally required reporting obligations to relevant state institutions within the set deadlines.

Recommendations and next steps

The report recommends addressing the identified cybersecurity and data protection risks, reviewing data retention periods, ensuring adequate capacity for the cybersecurity function, and revising the agreement with outsourcing provider Tet along with how such contracted services are managed. Evaluating the responsibility of individual officials falls outside the commission's mandate and is now a matter for law enforcement, to which all materials have been forwarded.

As previously reported, the early-August cyberattack exposed data of approximately 1.2 million individuals and around 200,000 legal entities, drawn from 18 years of payment records to the agency. Several CSDD officials resigned following the incident. The Prosecutor General's Office is conducting a review of possible violations, and the State Police have opened a criminal investigation.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category