Cybersecurity expert advises caution after CSDD data leak in Latvia
Following a major data leak at Latvia's Road Traffic Safety Directorate (CSDD), cybersecurity expert Elviss Strazdiņš warns that scammers could use the stolen data to make phishing attempts more convincing, urging people never to approve unsolicited Smart-ID requests.

After a large-scale data breach at Latvia's Road Traffic Safety Directorate (CSDD), cybersecurity expert Elviss Strazdiņš is urging residents to stay alert, warning that criminals could use the leaked data to craft more convincing fake emails, text messages and phone calls.
He explains that a message containing a recipient's name, car registration number or other precise personal details does not mean it actually came from CSDD or another official institution. Leaked data allows scammers to personalize messages, making the contact appear genuine. According to Strazdiņš, a personal identity number alone is usually not enough to cause immediate financial harm, but it can be used in follow-up fraud attempts.
The main danger — approving Smart-ID requests
The expert says he himself regularly receives unwarranted Smart-ID authentication requests from various financial institutions and other services. Approving such a request unknowingly could let a scammer log into someone's bank account or another service. That is why it is crucial never to approve a Smart-ID request you did not initiate yourself.
Strazdiņš recommends using different PIN codes for a phone and for Smart-ID, noting he has encountered cases where people, thinking they were unlocking their phone, actually entered their Smart-ID PIN and unintentionally approved a scammer's action. He also advises reviewing Smart-ID notification settings and always checking what action is being authenticated before confirming.
Anyone who has already approved a suspicious request or discovered their data being misused should contact their bank or service provider immediately and report the incident to the State Police.
As previously reported, a cyberattack on the night of August 7-8 resulted in the theft of personal data belonging to roughly 1.2 million individuals and around 200,000 legal entities from CSDD, gathered from payments made over the past 18 years. Following the breach, both the CSDD board and council decided to resign, while Transport Minister Rihards Kozlovskis has ordered an expedited internal investigation.


