Latvian Police Arrest Suspect in Electronics Repair Company Data Breach
Latvian authorities have arrested a 23-year-old man suspected of breaching at least two companies, stealing personal data and attempting extortion.

Latvian police have apprehended a 23-year-old individual believed to be responsible for hacking into at least two companies, compromising sensitive personal information and subsequently attempting to extort the victims. The initial cyberattack was detected in February, followed by a second incident in early September that targeted TSC, an electronics repair firm operating under the umbrella of the Latvian telecommunications group LMT. Investigators revealed that the suspect exploited vulnerabilities present in the companies' websites to gain unauthorized access to their databases, from which personal data was extracted.
Following the data exfiltration, the suspect allegedly contacted the affected companies via anonymous email accounts, demanding payment in exchange for withholding the disclosure of the stolen information. Law enforcement officials indicated that the suspect likely employed automated hacking tools to systematically scan websites and other online resources for security weaknesses, rather than engaging in highly targeted attacks against specific organizations. To further obscure his activities, the individual also utilized digital tools designed to conceal his true geographical location.
A search of the suspect's residence in Riga uncovered evidence suggesting potential attacks against other businesses, both within Latvia and internationally. These additional alleged incidents are currently under active investigation. The suspect, who was arrested on September 15 and whose identity remains undisclosed, has been formally charged in connection with the two confirmed cases. If convicted, he could face a prison sentence of up to five years.
Authorities have stated that the personal information stolen does not appear to have been disseminated to any third parties. TSC, the company most recently affected, disclosed the breach earlier this month, confirming that unidentified attackers had exploited a vulnerability in its website. This exploit allowed access to a database containing customer repair requests. The compromised data could have included names, contact details, device passcodes, bank account numbers, addresses, and even building access codes, depending on the information each customer had provided.
TSC, which specializes in repairing smartphones, smart devices, and household appliances, operates across Latvia, Lithuania, and Estonia. The company has not yet specified the exact number of customers impacted by the breach, nor has it publicly identified the specific vulnerability that was exploited. TSC has assured its customers that its IT systems are segregated from those of other LMT group companies, and that no other entities within the group, including LMT's core telecommunications network, were affected by this incident.