Ministry commission: CSDD cyberattack exposed gaps in security checks and network protection
A commission set up by the Transport Ministry, after reviewing August's cyberattack on Latvia's road traffic safety directorate CSDD, found several shortcomings in the agency's cybersecurity management, including insufficient security checks and no multi-factor authentication.

Latvia's Transport Ministry has announced that a commission it established has completed its assessment of the cyberattack that hit the Road Traffic Safety Directorate (CSDD) in August, identifying multiple errors and gaps in the agency's cybersecurity management.
Shortcomings identified
The commission concluded that CSDD had not ensured adequate coverage of security checks. It also found insufficient network protection, and noted that multi-factor authentication — generally regarded as a basic safeguard against unauthorized access to systems — had not been implemented.
The Transport Ministry stated that these deficiencies collectively point to weaknesses in CSDD's cybersecurity management system, which may have contributed to or facilitated the cyberattack that occurred in August.
The ministry's statement did not provide further details about the attack itself or its consequences.

/nginx/o/2026/09/18/17925152t1h0b44.jpg)
