A cyberattack against Latvia’s Road Traffic Safety Directorate (CSDD) has exposed personal information connected to approximately 1.2 million people, making the incident particularly significant in a country with a population of just over 1.8 million.

 

 

The scale of the breach became public on August 18, more than a week after attackers initially gained access over the weekend of August 8-9. Authorities acknowledged the cyberattack on August 13, but the number of people affected and the extent of the compromised information remained unclear for several more days.

Latvian President Edgars Rinkēvičs has described the incident as a serious national security concern. He also questioned whether the organization’s current leadership could remain in place after an incident that damaged public confidence in the CSDD.

The attacker has not been publicly identified. According to the CSDD, the compromised information originated from payment receipts dating as far back as 2008.

The exposed records contain combinations of personal identification numbers or company registration numbers, names, payment amounts and dates, vehicle registration numbers, and addresses recorded when particular services were provided. For individuals, an address could correspond to information that appeared on a vehicle registration certificate at the time.

CSDD IT chief Māris Puriņš said customer email addresses and telephone numbers were not compromised. Address information was also incomplete in some of the affected records.

Despite those limitations, cybersecurity specialists have warned that the stolen information could still be valuable to criminals. Details linking an individual’s identity with a vehicle, address, and previous transactions could allow scammers to construct highly personalized phishing emails, text messages, or telephone scams.

Varis Teivāns, deputy head of Latvia’s national cybersecurity organization Cert.lv, warned that criminals possessing several accurate details about a potential victim can make a scam appear considerably more convincing. People have therefore been advised to treat unexpected communications supposedly connected to the CSDD with caution and verify information through official CSDD channels rather than following links contained in unsolicited messages.

The agency says it has introduced additional restrictions intended to prevent unauthorized parties from obtaining vehicle information using national registration numbers. Another targeted cyberattack occurred after the original breach, according to the CSDD, but newly implemented security measures successfully blocked it.

The State Data Inspectorate has been notified, while the CSDD continues to cooperate with authorities investigating the attack and attempting to identify those responsible.

Despite the scale of the data exposure, the incident has not disrupted regular CSDD operations. In-person services and the agency’s online e-CSDD services remain available while the investigation continues.

Leave a Reply