Latvian officials resign after cyberattack exposes data on 1.2 million people
Latvia’s road traffic agency confirmed that hackers stole data connected to about two-thirds of the country’s population in a major cyberattack that has prompted calls for senior officials to resign.
The Road Traffic Safety Directorate, known as CSDD, said Tuesday that its investigation found hackers had accessed data from payment receipts dating back to 2008. The breach affected records belonging to more than 1.2 million people and 200,000 businesses and other legal entities. Latvia has a population of just over 1.8 million.
CSDD is the state agency responsible for vehicle registration, driver’s licenses and other road safety services and operates under Latvia’s Transport Ministry.
The stolen information includes personal identification numbers or company registration numbers, vehicle license plate numbers, payment amounts and dates, as well as addresses listed on vehicle registration certificates.
CSDD said customer phone numbers and email addresses were not affected and that address information was incomplete in some records. Usernames and passwords were also not compromised.
The agency said its day-to-day operations had not been disrupted and that both online and in-person services remained available.
Latvia’s computer emergency response team (CERT.LV) warned that criminals could use the stolen information in social engineering and fraud schemes.
CSDD said it is still investigating the attack and working to identify those responsible. The agency has also restricted access to a service that allows users to look up information about a vehicle, including its make and model, using its license plate number.
The agency said it faced another attempted cyberattack over the weekend but was able to block it following security improvements introduced after the initial breach.
Complex attack
CSDD first disclosed the breach last week, describing it as a “complex” cyberattack in which third parties gained partial access to systems containing historical payment receipt data.
At the time, the agency said it had worked with cybersecurity authorities to identify and completely block the “methods and channels” used by the attackers.
“The information obtained so far indicates that the attack was targeted and that prior preparation was made for its implementation,” said Varis Teivans, deputy head of CERT.LV. “The nature of the attack and the set of methods used also indicate the technical competence of the attackers.”
CERT.LV later told Latvian public broadcaster LSM the hackers had exploited a vulnerability in a CSDD system exposed to the internet and that several mandatory cybersecurity requirements had not been met.
The incident has since escalated into a political controversy over responsibility for the attack.
President Edgars Rinkevics said Tuesday the attack posed “a significant threat to national security” and argued that CSDD’s leadership should step down.
“The CSDD's reputation and public trust in this institution have been undermined,” Rinkevics said in a post on X. “Under such circumstances, the CSDD management must not continue its work.”
Latvian member of Parliament Andris Kulbergs also called for CSDD’s management and supervisory board to resign. On Wednesday morning, the agency’s supervisory board submitted its resignation.
CSDD chief Aivars Aksenoks, a former mayor of Riga, said Wednesday that he was also preparing to leave once he had helped complete the investigation and address the consequences of the attack.
“I can't just slam the door behind me and leave,” Aksenoks told local media. “I want to really help resolve the situation first and then, I think I'll definitely stop working.”
“The consequences have been severe, we are very aware of our responsibility for this,” he added. “I am also ready to leave this job.”
Shifting blame
Aksenoks said responsibility for the breach may not lie with CSDD alone, pointing to Latvian telecom and technology company Tet, which provides some of the agency’s IT infrastructure and security monitoring.
CSDD has a five-year contract with Tet covering IT infrastructure maintenance and monitoring, including some firewall and incident-monitoring functions, according to Aksenoks.
He said Tet did not detect the intrusion or alert the agency. Instead, CSDD employees discovered the attack themselves and stopped it within several hours.
Tet has pushed back against suggestions that responsibility can already be assigned.
The company’s chairman, Uldis Tatarcuks, said investigators first need to determine how and when the attackers gained access, which systems were compromised and where security measures failed. The company also said it is responsible for only certain parts of CSDD’s IT infrastructure, not the agency’s entire network.
Latvian cybersecurity and data protection authorities are continuing to investigate the incident, while state police have opened criminal proceedings.
The incident follows another significant cyberattack against a Latvian state-owned organization earlier this summer. In June, state-owned forestry company LVM suffered a ransomware attack that disrupted its mapping platform, hunting application and systems used to exchange information with contractors and customers.
The attack drew extra scrutiny because LVM had worked on Latvia’s electronic voter registration system, which allows people to vote at any polling station. Officials said the election system was not affected because it was developed separately and its source code was not stored on LVM’s network.
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.



