Latvia's Road Traffic Safety Directorate (CSDD), the state agency responsible for vehicle registration and driver's licenses, has confirmed a significant data breach impacting approximately 1.2 million individuals and 200,000 businesses. This figure represents about two-thirds of Latvia's total population of 1.8 million. The breach led to the exposure of data from payment receipts dating back to 2008.
Information compromised in the attack includes personal identification numbers or company registration numbers, vehicle license plate numbers, payment amounts and dates, and addresses listed on vehicle registration certificates. The CSDD stated that customer phone numbers, email addresses, usernames, and passwords were not affected, and that address information was incomplete in some records. Despite the breach, the agency's day-to-day operations, including online and in-person services, remained uninterrupted.
Latvia's computer emergency response team (CERT.LV) cautioned that the stolen information could be leveraged by criminals for social engineering and fraud schemes. The CSDD has since restricted access to a public service that allowed users to look up vehicle information using a license plate number. The agency also reported successfully blocking a subsequent cyberattack attempt over the weekend, attributing the defense to security enhancements implemented after the initial breach.
The CSDD initially disclosed the incident last week, characterizing it as a "complex" cyberattack where unauthorized third parties gained partial access to systems containing historical payment receipt data. CERT.LV indicated that the attackers exploited a vulnerability in a CSDD system exposed to the internet, and that several mandatory cybersecurity requirements had not been met. The nature and methods employed in the attack suggest a high level of technical competence and prior preparation by the attackers.
The incident has escalated into a political controversy, prompting calls for accountability. Latvian President Edgars Rinkevics stated that the attack posed "a significant threat to national security" and called for the CSDD's leadership to resign, citing a loss of public trust. Member of Parliament Andris Kulbergs echoed these sentiments. Following this, the CSDD's supervisory board submitted its resignation. CSDD chief Aivars Aksenoks also announced his intention to resign after assisting with the ongoing investigation and addressing the consequences of the attack.
Aksenoks suggested that responsibility for the breach might extend beyond the CSDD, pointing to Tet, a Latvian telecom and technology company that provides some of the agency's IT infrastructure and security monitoring services under a five-year contract. He claimed that Tet, which is responsible for certain firewall and incident-monitoring functions, failed to detect the intrusion or alert the agency, with CSDD employees discovering and stopping the attack themselves within hours.
Tet's chairman, Uldis Tatarcuks, has pushed back against premature blame, emphasizing the need for investigators to first determine the precise entry points, timing of access, compromised systems, and specific security failures. Tet clarified that its responsibilities cover only specific parts of the CSDD’s IT infrastructure, not the entire network.
Latvian cybersecurity and data protection authorities are continuing their investigation into the incident, and state police have initiated criminal proceedings. This breach follows another significant cyberattack earlier this summer against LVM, a state-owned forestry company, which experienced a ransomware attack in June that disrupted its mapping platform, hunting application, and systems for exchanging information with contractors and customers. Although LVM had worked on Latvia’s electronic voter registration system, officials confirmed that the election system was unaffected as it was developed separately and its source code was not stored on LVM’s network.






