Latvia's consumer rights agency reports data breach exposing hundreds of contacts
A cybersecurity incident was detected in a system run by Latvia's Consumer Rights Protection Centre (PTAC), exposing contact details of hundreds of company representatives and agency staff. The affected system has been shut down, and no oversight data submitted by companies was compromised.

Latvia's Consumer Rights Protection Centre (PTAC) has reported a data security incident affecting one of the information systems under its management. The breach hit the so-called Remote Statistical Data Extraction System (ASDIS), which PTAC uses to supervise licensed businesses.
A low-risk classification
ASDIS is classified as a Class C security system, the lowest risk category among information systems. It operates within a network infrastructure equipped with an early-warning sensor system maintained by Cert.lv, Latvia's cyber incident response institution, and meets the country's minimum cybersecurity requirements.
What was exposed
An ongoing investigation indicates that attackers obtained contact information belonging to companies licensed by PTAC, including consumer lending service providers, out-of-court debt collection firms, and package travel service providers. In total, contact details of 697 company representatives and 34 PTAC officials were extracted, including names, email addresses and phone numbers.
PTAC noted that most of this information is already publicly available through other registers, such as the Open Data Portal. The agency also stated that the incident did not compromise the oversight data submitted to it by supervised companies.
Next steps
The affected system has now been taken offline, and PTAC has notified all its users about the resulting unavailability. The agency stressed that, given the current unstable geopolitical situation, it is essential to strengthen the security of technological resources and allocate the necessary funding — a need previously highlighted by the Ministry of Economics during a Cabinet of Ministers session on cybersecurity issues.

/nginx/o/2026/02/03/17421731t1hbd5e.jpg)
