PM Kulbergs explains how CSDD cyberattack occurred
Prime Minister Andris Kulbergs said the cyberattack on Latvia's Road Traffic Safety Directorate (CSDD) exploited the agency's 'Medical' platform, used by around 200 doctors to enter drivers' medical certificates. He shared the explanation on social media.
/nginx/o/2026/08/20/17865393t1h51a3.jpg)
Prime Minister Andris Kulbergs has publicly addressed the recent cyberattack on the Road Traffic Safety Directorate (CSDD), Latvia's road traffic authority, outlining how the breach unfolded.
The weak point was the medical module
According to Kulbergs, the intrusion occurred through a section of the CSDD's system known as "Medical". This platform is used by doctors to enter medical certificates confirming that a driver is fit, health-wise, to operate a vehicle.
The prime minister specified that this part of the system is regularly used by approximately 200 doctors across the country. That broad base of access may have created an additional point of vulnerability that attackers were able to exploit.
Public disclosure of the incident
Kulbergs chose to inform the public directly via social media, offering a technical explanation of how the attack took place. The move signals the government's intent to maintain transparency regarding the cybersecurity of state institutions.
At this stage, it remains unclear how extensive the damage from the breach is, or whether the personal data of drivers or doctors was compromised as a result. It is also not yet known whether CSDD has made, or plans to make, changes to the security of the "Medical" platform to prevent similar incidents in the future.


