Cyberattack on Latvia's State Forests: firm left vulnerability unfixed for two years after warning
State forestry company LVM failed to fix a system vulnerability for two years despite being warned by Cert.lv, and that flaw was exploited by a hacker who stole and leaked internal data. The case was investigated by the programme 'de facto'.

The Latvian television programme "de facto" has found that the hacker who stole and leaked internal data from state forestry company "Latvijas Valsts meži" (LVM) was able to carry out the attack because the company had left a known system vulnerability unaddressed for a long time.
LVM representatives acknowledged that if the attacker had tried to breach the system two weeks later, the attempt would most likely have failed, since a system update was already scheduled around that time.
Warning issued two years earlier
It has emerged that the company had been informed about the vulnerability two years before the attack took place, with the warning coming from Cert.lv, Latvia's cyber incident response institution. "De facto" examined why LVM did not act on that warning at the time and left the flaw unresolved.
According to publicly available information, the vulnerability was linked to a misinterpretation of the "≥" (greater than or equal to) symbol within the system, which created conditions that could be exploited for an attack.
Details remain unclear as to exactly what actions, or lack thereof, allowed the vulnerability to go unfixed for two years, but the question of LVM's response to the warning it received remains at the centre of the programme's investigation.

/nginx/o/2026/02/25/17477377t1h9374.jpg)
