In Latvia, a cyberattack resulted in the leak of data on 1.2 million people
In Latvia, following a cyberattack on the Road Traffic Safety Directorate (CSDD), cybercriminals obtained personal data belonging to 1.2 million people. The CSDD reported this on August 18, according to LSM English.
According to the agency, the attackers obtained information from payment receipts dating back to 2008 and later. This information includes a personal identification number or company registration number, a person’s first and last name or a company name, the payment amount and date, the vehicle registration number, and the address on file at the time the service was received.
Maris Purins, head of the CSDD’s IT department, stated that the agency’s customers’ phone numbers and email addresses were not compromised. He also noted that address information is not included in all of the records obtained by the attackers.
For more breaking news, follow the UA.News Telegram channel.
The CSDD reported that it is continuing its investigation into the cyberattack and is cooperating with the relevant authorities to identify the perpetrator. The agency has restricted unauthorized access to vehicle information based on state registration numbers, which previously allowed users to retrieve data on a vehicle’s make and model. According to Purins, over the weekend the CSDD also suffered a targeted cyberattack, which was successfully blocked thanks to enhanced security measures.
Varis Teivans, deputy head of Cert.lv, warned that the information obtained by the attackers could be used for social engineering and fraud. He explained that personal data and details of previous payments could help scammers create more convincing personalized messages, emails, or phone calls. The CSDD advised users to verify information regarding its communications on the e.csdd.lv website or in the mobile app and not to click on any links in the messages they receive.
The agency reported the incident to the Latvian State Data Inspectorate. The provision of CSDD services, including those via the e-CSDD system, was not affected.