VYPR
breachPublished Aug 19, 2026· 1 source

Latvian Road Agency Suffers Major Cyberattack, Exposing Data of 1.2 Million Citizens

Hackers breached Latvia's road traffic agency, stealing sensitive data linked to approximately 1.2 million individuals, prompting calls for resignations and raising national security concerns.

Latvia's Road Traffic Safety Directorate (CSDD) has confirmed a significant cyberattack that resulted in the theft of data belonging to over 1.2 million individuals and 200,000 businesses, representing roughly two-thirds of the country's population. The breach, which affected payment receipts dating back to 2008, included personal identification numbers, company registration numbers, vehicle license plates, payment amounts, and dates. While customer phone numbers, email addresses, usernames, and passwords were not compromised, the exposed information poses a risk for social engineering and fraud schemes, according to CERT.LV, Latvia's national computer emergency response team.

The attack, described as "complex" and "targeted" by authorities, exploited a vulnerability in a CSDD system exposed to the internet, with CERT.LV noting that several mandatory cybersecurity requirements had not been met. The agency has since restricted access to a vehicle lookup service and implemented security improvements after successfully blocking a subsequent attempted attack over the weekend. Despite the breach, CSDD stated that its day-to-day operations remain unaffected, with online and in-person services continuing as normal.

The scale and impact of the breach have triggered a political crisis, with President Edgars Rinkevics calling for the resignation of CSDD's leadership, stating that the agency's reputation and public trust have been undermined. The CSDD's supervisory board has submitted its resignation, and agency chief Aivars Aksenoks has indicated his intention to step down after assisting with the investigation and aftermath.

Aksenoks has suggested that responsibility might not solely lie with CSDD, pointing to IT infrastructure provider Tet, which is contracted for maintenance and security monitoring. However, Tet has pushed back, emphasizing the need for a thorough investigation to determine the exact cause and point of failure before assigning blame, and noting their limited scope of responsibility within CSDD's network.

State police have initiated criminal proceedings, and data protection authorities are continuing their investigation into the incident. This breach follows another major cyberattack earlier in the summer against LVM, a state-owned forestry company, highlighting a concerning trend of cyber threats targeting Latvian state organizations.

The incident underscores the critical importance of robust cybersecurity measures and adherence to mandatory requirements, especially for state agencies handling vast amounts of sensitive personal data. The ongoing investigation aims to uncover the full extent of the compromise and identify the perpetrators, while the political fallout continues to unfold.

Synthesized by Vypr AI