Wednesday, 19 August 2026
Rīga TV

World and Latvian news in one place

LatviaPublished: 19 August 2026 at 08:01

PM calls on CSDD leadership and council to resign after cyberattack

Latvia's Prime Minister has demanded that the road traffic agency CSDD's board and council resign following a massive data breach, while the agency's board chairman says he sees no reason to step down.

Foto: Delfi

Latvia's Prime Minister has sharply criticized the leadership of the Road Traffic Safety Directorate (CSDD) for its public comments following a recent cyberattack on the agency, saying neither the board nor the council acted as responsible stewards. The PM called on CSDD's leadership to submit resignations by the next day, warning of consequences otherwise.

A coalition politician also publicly urged the resignations on social media, citing the massive scale of the leaked private and legal-entity data and its potential harm to residents and national security.

Multiple reviews underway

The Prime Minister had earlier instructed the transport minister, as the state's representative holding CSDD's capital shares, to assess the board and council's handling of the cyber incident. The transport minister in turn ordered a formal service inquiry into the responsibility of board and council members.

CSDD board chairman Aivars Aksenoks said on Tuesday he does not plan to resign, stating he currently sees no violations on the board's part. He explained that CSDD's IT system is complex, serving connections to dozens of institutions, and that gaps in compliance with cabinet-mandated security requirements are being addressed gradually, since those rules were adopted only last year without a transition period.

Aksenoks added that CSDD's council has ordered an emergency audit of the agency, and that its internal Information Systems Security Committee has launched an in-depth review of all matters related to the attack.

Parliament to debate the issue

Several factions in the Saeima are set to discuss the incident on Wednesday. A representative of the cyber incident response institution Cert.lv said on Tuesday that the attack exposed data belonging to roughly 1.2 million individuals and about 200,000 legal entities, gathered from CSDD payment records spanning the past 18 years. The breach exploited a vulnerability in a CSDD system accessible from the internet, and investigators found several cabinet-mandated security requirements for class-A information systems — including multi-factor authentication and penetration testing — had not been followed.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category