< Back to situation

[REVISION HISTORY]

Latvia CSDD cyberattack and data breach

Updated 14 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-08 16:22 UTC → 2026-09-18 09:36 UTC · added removed

The Latvian Road Traffic Safety Directorate (CSDD) was targeted by a sophisticated cyberattack that resulted in unauthorized access to its IT systems. The breach, which occurred during the night of August 7–8, involved the theft of personal data belonging to approximately 1.2 million individuals and 200,000 legal entities, with stolen records spanning the previous 18 years. Compromised information includes names, personal identification codes, addresses, vehicle registration numbers, and historical payment details. CSDD has clarified that phone numbers, email addresses, bank details, and e-CSDD login credentials were not compromised. The incident has triggered a political crisis. Prime Minister Andris Kulbergs characterized the attack as a potential foreign hybrid operation and criticized CSDD’s security protocols, stating the agency had left its “cybersecurity doors wide open” due to a lack of required multi-factor authentication. He also raised allegations of a “total conflict of interest” regarding an individual holding simultaneous positions in CSDD’s IT department and its server service provider. Following the breach, President Edgars Rinkēvičs called for the resignation of CSDD leadership, while Transport Minister Rihards Kozlovskis ordered an expedited service investigation. Investigations A subsequent investigation by CERT.LV revealed a commission from the Ministry of Transport identified multiple cybersecurity failures that facilitated the breach. The commission found that vulnerabilities in the “med. csdd. lv” web application allowed attackers exploited a vulnerability initial access. Specific deficiencies included incomplete security audits, insufficient network protection, flaws in software development, and a publicly accessible system, noting lack of multi-factor authentication. Minister Kozlovskis noted that CSDD failed to meet mandatory security requirements for Class A information systems. In response to these errors and instances of inaction prevented the leak, full mitigation of cyberattack risks. While the State Police have launched a criminal investigation. To assist affected users, CSDD has enabled a feature commission focused on technical recommendations, the e.csdd.lv portal, allowing clients to authenticate and verify which specific categories assessment of their data were extracted. The agency noted the attacker obtained unstructured and incomplete data from payment receipt tables and official responsibility has advised users been referred to utilize the CERT.LV ‘DNS firewall’ application law enforcement agencies to mitigate risks from malicious communications. Following the breach, CERT.LV reported a surge in fraudulent activities throughout August, including ongoing phishing campaigns impersonating the CSDD. address questions of legal compliance and accountability.

Versions

  1. 2026-09-18 09:36 UTC Latvia CSDD cyberattack and data breach
  2. 2026-09-08 16:22 UTC Latvia CSDD cyberattack and data breach
  3. 2026-08-27 08:03 UTC Latvia CSDD cyberattack and data breach
  4. 2026-08-25 22:10 UTC Latvia CSDD cyberattack and data breach
  5. 2026-08-25 04:23 UTC Latvia CSDD cyberattack and data breach
  6. 2026-08-23 04:11 UTC Latvia CSDD cyberattack and data breach
  7. 2026-08-21 07:42 UTC Latvia CSDD cyberattack and data breach
  8. 2026-08-20 13:07 UTC Latvia CSDD cyberattack and data breach
  9. 2026-08-20 05:29 UTC Latvia CSDD cyberattack and data breach
  10. 2026-08-19 11:55 UTC Latvia CSDD cyberattack and data breach
  11. 2026-08-19 08:06 UTC Latvia CSDD cyberattack and data breach
  12. 2026-08-19 07:39 UTC Latvia CSDD cyberattack and data breach
  13. 2026-08-18 20:18 UTC Latvia CSDD cyberattack and data breach
  14. 2026-08-18 15:24 UTC Latvia CSDD cyberattack and data breach
  15. 2026-08-18 14:35 UTC Latvia CSDD cyberattack and data breach

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.