Consumer Rights Protection Center system hacked in Latvia
In Latvia, attackers obtained contact details from the information system of the Consumer Rights Protection Center (PTAC). The data concerns representatives of licensed companies and agency officials, LSM English reports.
What data the attackers obtained
The incident affected the ASDIS Remote Statistical Data Acquisition System, which PTAC uses to supervise licensed business entities. The center noted that ASDIS belongs to security class C systems — the lowest risk level — and meets minimum state cybersecurity requirements.
According to preliminary data, the hack occurred on September 1. As a result of the incident, the attackers obtained contact information of consumer credit service providers, out-of-court debt collection companies, and providers of package travel services.
More current news is available on the UA.News Telegram channel Telegram.
This includes the first names, surnames, email addresses and phone numbers of 697 business representatives and 34 PTAC officials. The center stated that most of this information is already available in other public registers, although 106 contacts had not previously been made public.
The system is currently closed
The ASDIS system was closed after the incident. Gints Malkalnietis, a cyberincident prevention expert at CERT.lv, assessed the risks from the leak as relatively low. According to him, this attack was much simpler than the recent cyberattacks on Latvia's State Forests and the Road Traffic Safety Directorate, CSDD.
CERT.lv also reported that the attackers were not from Latvia, Russia or other European countries. The agency is not disclosing additional information about them at this time. According to the expert, the stolen data was published on a popular hacker forum.