$ 44.71 € 52.14 zł 12.1
+12° Kyiv +11° Warsaw +19° Washington

Latvia’s CSDD reported cyberattack with delay

Lev Shevtsov 24 August 2026 09:00
Latvia’s CSDD reported cyberattack with delay

Latvia’s Road Traffic Safety Directorate (CSDD) reported a cyberattack with a delay. According to LSM English, citing a De Facto investigation, data on 1.2 million individuals and 200,000 legal entities may have been stolen during the incident. This is the second-largest data leak in Latvia’s history.

The attacker entered the system overnight from August 7 to 8 through the Medical platform, which around 200 doctors use to submit drivers’ medical certificates. Cert.lv considers it likely that the same attacker also unsuccessfully attempted to gain access to other state systems.

Incident reporting

CSDD informed the cyber incident response organization Cert.lv only on the evening of August 10. After its specialists became involved, the scale of the attack began to emerge on the evening of the following day and on the morning of August 12. Latvia’s State Data Inspectorate did not receive notification of the leak within the 72-hour period established by law.

The inspectorate is conducting a review to establish the circumstances of the case and decide whether to initiate proceedings over an administrative offence. According to De Facto, CSDD is responsible for the security of the stored data.

More current news is available on the UA.News Telegram channel Telegram.

Tet, which provides CSDD with IT infrastructure services under a €9 million contract, learned unofficially about the possible attack on August 10, when directorate employees reported connection problems. The company received an official letter from CSDD on Friday, almost a week after the system intrusion.

Investigation and resignations

Tet stated that its internal review indicated an attack through an application managed by CSDD itself. According to the company’s assessment, the software and cybersecurity of this application were not within its responsibility. Tet also noted that it continuously monitored traffic under the contract, but data flow load alone is not an indication of a cyberattack.

Latvia’s State Police independently launched a preliminary review and, after confirming the facts, opened criminal proceedings over unauthorized access to critical infrastructure by bypassing security settings and malicious actions with serious consequences. Police are also checking whether the data have appeared on the black market and will assess the possible liability of the system administrator if evidence is available.

After the incident became public, CSDD’s supervisory board resigned. On August 19, Transport Minister Rihards Kozlovskis also demanded the resignation of the directorate’s board, which agreed to leave office. An interim board was subsequently appointed at CSDD. Earlier, Cert.lv had offered the institution state services for the timely detection of abnormal data leaks, but CSDD declined them.

Read us on Telegram and Sends

Download our app