Wednesday, 19 August 2026
Rīga TV

World and Latvian news in one place

RegionsPublished: 19 August 2026 at 08:01

PM demands resignation of CSDD board and council after cyberattack

Prime Minister Andris Kulbergs has called on the leadership of Latvia's Road Traffic Safety Directorate (CSDD) to resign following a major cyberattack, though CSDD's chairman says he sees no grounds to step down.

Foto: Bauskas Dzīve

Prime Minister Andris Kulbergs posted a video message on X calling on the board and supervisory council of the Road Traffic Safety Directorate (CSDD) to resign. He expressed outrage over their public comments following a recent cyberattack, saying neither body had acted responsibly. Kulbergs urged them to submit resignations by the next day, warning of consequences otherwise.

Earlier, the prime minister had instructed Transport Minister Rihards Kozlovskis, as the state's representative in CSDD's capital shares, to assess the board and council's conduct regarding the cyber incident. The minister in turn ordered an internal review of their responsibility.

CSDD chief has no plans to step down

CSDD board chairman Aivars Aksenoks said on Tuesday he currently sees no violations by the board and does not intend to resign. He explained that CSDD's IT systems are complex, serving connections to dozens of institutions. Aksenoks acknowledged the investigation found several requirements set by Cabinet regulations were not met, but noted these regulations were adopted only last year without a transition period, and that security checks were being brought into compliance gradually.

He added that the council had ordered an emergency audit of the agency, while CSDD's internal Information Systems Security Committee is conducting a deeper review of all matters related to the attack. Several parliamentary factions are expected to discuss the case in the Saeima on Wednesday.

Over a million people affected

Varis Teivāns, deputy head of cybersecurity body Cert.lv, said the attackers obtained data on roughly 1.2 million individuals and about 200,000 legal entities, gathered from payments made to CSDD over the past 18 years. According to Teivāns, the breach exploited a vulnerability in an internet-facing CSDD system, and several mandatory requirements for Class A information systems — including multi-factor authentication and penetration testing — had not been implemented.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category