PM Kulbergs demands resignation of CSDD leadership after cyberattack
Prime Minister Andris Kulbergs has called on the leadership and supervisory board of Latvia's Road Traffic Safety Directorate (CSDD) to resign following a major cyberattack, criticizing their handling of the incident. The CSDD board chairman says he does not plan to step down.

Prime Minister Andris Kulbergs, in a video message posted on "X", called on the management board and supervisory council of the Road Traffic Safety Directorate (CSDD) to resign immediately following a recent cyberattack on the agency. He expressed outrage over how both bodies had commented on the incident, saying they had failed to act as responsible stewards of the institution.
Kulbergs said bluntly that resignations should be submitted by the next day, or consequences would follow.
Prior steps
Earlier, the prime minister had tasked Transport Minister Rihards Kozlovskis, acting as the state's capital shareholder representative, with assessing the actions of CSDD's leadership regarding the cyber incident. The minister has since ordered a service inspection to determine the accountability of board and council members.
CSDD leadership response
CSDD board chairman Aivars Aksenoks said on Tuesday that he does not intend to resign, stating he currently sees no violations on the board's part. He explained that CSDD's IT system is complex, as it provides connections to dozens of different institutions. Regarding findings that several security requirements set by the Cabinet of Ministers had not been met, Aksenoks noted that the relevant regulations were only adopted last year without a transition period, and that improvements are being implemented gradually. He added that the council had ordered an emergency audit, while the agency's internal security committee is conducting an in-depth review of matters related to the cyberattack.
The Saeima is expected to discuss the incident on Wednesday, with several factions weighing in.
Scale of the breach
According to Varis Teivāns, deputy head of the cybersecurity institution Cert.lv, the attack resulted in the theft of personal data belonging to approximately 1.2 million individuals and around 200,000 legal entities, drawn from payment records spanning the last 18 years. The attackers exploited a vulnerability in a CSDD system accessible over the internet. The investigation also found that several Cabinet-mandated requirements for Class A information systems, including multi-factor authentication and penetration testing, had not been followed.


