There has been a cyberattack on Latvia’s road traffic agency, which reportedly exposed data tied to roughly 1.2 million people. Details are here but here’s the TL:DR:
Questions might also be reasonably be asked concerning why it has taken so long to inform the general public that it is highly likely that some of their details have been stolen. The cyber attack happened over the weekend of August 8th/9th. The first public admission that it had taken place came on August 13th, and then on August 14th, officials still could not or would not specify how big the breach was. It then took another 4 days for the full enormity of the data stolen to be announced today.
President Edgars Rinkēvičs waded into the issue on August 18th, suggesting – in a social media post – that the “massive data leak” poses “a significant threat to national security”. He also dropped a hint that heads must roll – without explicitly saying so – adding that “The CSDD’s reputation and public trust in this institution have been undermined. Under such circumstances, the CSDD management must not continue its work.”
The cyberattacker, who has yet to be officially identified, has obtained information regarding data contained in payment receipts dating back to 2008.
According to the CSDD, the following data has fallen into the hands of the perpetrators:
- personal identification number or company registration number;
- first name and surname or company name;
- payment amount;
- date of payment;
- vehicle registration number;
- address registered on the date the service was received, for example, the address stated on the vehicle registration certificate.
Joshua Marpet, Sr. Product Security Consultant, Finite State (https://www.linkedin.com/in/joshuaviktor)
“When you have system access exposed to the internet, and several mandatory cybersecurity requirements had not been met? Bad operator! 30 days, no computer!
“When you are a commercial operation, protecting your customer’s data is a mandate, an absolute. You don’t get a choice. You protect it, or the cyber-roaches will smell the sweet sweet data, and come up through the drains, under the door, they’ll squeeze through the suggestion of a crack in the wall. And they’ll take it all, or as least as much as they can get away with.
“When you’re a government operation, protecting the identities of the MAJORITY of the residents of the entire country (1.2million out of 1.8 million total), you better protect that Personally Identifiable Information. And not being sure who is responsible for what systems/barriers/security gateways? That’s a path to failure. You must, must, must, have a Shared Responsibility Model between you and the service provider. Who is responsible for what? Having a model matrix’ed out makes it easy to see where the gaps are.
“Not having one? Priceless, for the bad guys.”
Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)
“Breaches like this are a reminder that security is also about limiting impact. The most resilient organizations assume that some controls will eventually fail and design their environments so that no single incident exposes data at massive scale. Strong segmentation, data minimization, and tightly managed access can help turn a potentially broad breach into a contained event, while giving security teams more time and options to respond effectively.
“Organizations that manage large volumes of citizen data should focus on reducing the value of any single target. That means limiting data collection to what is truly needed, separating sensitive datasets, encrypting information both in transit and at rest, and restricting bulk access to a small number of tightly monitored systems and users. Just as important are rapid detection and response capabilities that can identify unusual access patterns early and contain a compromise before it spreads. The goal is to build layers of resilience so that even when an attacker gains access, the amount of data exposed and the resulting impact remain limited.”
Denis Calderone, COO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“Not to reduce the importance of the vulnerability that was exploited or the outsourced monitoring contract that failed to catch it, but what seems equally important here is why a road traffic agency was holding 18 years of payment data tied to national identification numbers for two-thirds of Latvia’s population. CSDD’s payment systems contained transaction records going back to 2008. Names, national ID numbers, home addresses, vehicle plates, payment amounts. For 1.2 million people in a country of 1.8 million. Latvia’s own accounting law requires a five-year retention period for source documents like payment receipts, not eighteen. You can’t steal data that’s already been deleted. If CSDD had enforced a reasonable retention policy and purged records older than five to seven years, the blast radius shrinks from a national-scale incident to something far more contained.
“This is the second time in a week we’re looking at a centralized government database holding national identification numbers for a significant portion of an entire country’s population getting compromised. Poland’s MyDr EMR breach affected 18.8 million PESEL numbers just days ago. Now Latvia’s CSDD exposed 1.2 million personal identification codes. Government systems accumulate decades of sensitive data because nobody builds the process to delete it when it’s no longer needed.
“Data minimization isn’t just a GDPR compliance checkbox. It is arguably the single most cost-effective breach-impact control available. CSDD was reportedly paying nine million euros over five years for IT infrastructure and round-the-clock monitoring from Tet. That monitoring failed to detect the attack. Several mandatory cybersecurity requirements hadn’t been met. But even if every one of those controls had worked perfectly, 18 years of sensitive data was still sitting in a system that didn’t need to hold it. The retention policy was the vulnerability.”
People who are victims of this hack had better be on the lookout for scams, phishing and the like headed their way as there is no good outcome for this.
Related
This entry was posted on August 20, 2026 at 8:00 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Latvia breach Exposed
There has been a cyberattack on Latvia’s road traffic agency, which reportedly exposed data tied to roughly 1.2 million people. Details are here but here’s the TL:DR:
Questions might also be reasonably be asked concerning why it has taken so long to inform the general public that it is highly likely that some of their details have been stolen. The cyber attack happened over the weekend of August 8th/9th. The first public admission that it had taken place came on August 13th, and then on August 14th, officials still could not or would not specify how big the breach was. It then took another 4 days for the full enormity of the data stolen to be announced today.
President Edgars Rinkēvičs waded into the issue on August 18th, suggesting – in a social media post – that the “massive data leak” poses “a significant threat to national security”. He also dropped a hint that heads must roll – without explicitly saying so – adding that “The CSDD’s reputation and public trust in this institution have been undermined. Under such circumstances, the CSDD management must not continue its work.”
The cyberattacker, who has yet to be officially identified, has obtained information regarding data contained in payment receipts dating back to 2008.
According to the CSDD, the following data has fallen into the hands of the perpetrators:
Joshua Marpet, Sr. Product Security Consultant, Finite State (https://www.linkedin.com/in/joshuaviktor)
“When you have system access exposed to the internet, and several mandatory cybersecurity requirements had not been met? Bad operator! 30 days, no computer!
“When you are a commercial operation, protecting your customer’s data is a mandate, an absolute. You don’t get a choice. You protect it, or the cyber-roaches will smell the sweet sweet data, and come up through the drains, under the door, they’ll squeeze through the suggestion of a crack in the wall. And they’ll take it all, or as least as much as they can get away with.
“When you’re a government operation, protecting the identities of the MAJORITY of the residents of the entire country (1.2million out of 1.8 million total), you better protect that Personally Identifiable Information. And not being sure who is responsible for what systems/barriers/security gateways? That’s a path to failure. You must, must, must, have a Shared Responsibility Model between you and the service provider. Who is responsible for what? Having a model matrix’ed out makes it easy to see where the gaps are.
“Not having one? Priceless, for the bad guys.”
Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)
“Breaches like this are a reminder that security is also about limiting impact. The most resilient organizations assume that some controls will eventually fail and design their environments so that no single incident exposes data at massive scale. Strong segmentation, data minimization, and tightly managed access can help turn a potentially broad breach into a contained event, while giving security teams more time and options to respond effectively.
“Organizations that manage large volumes of citizen data should focus on reducing the value of any single target. That means limiting data collection to what is truly needed, separating sensitive datasets, encrypting information both in transit and at rest, and restricting bulk access to a small number of tightly monitored systems and users. Just as important are rapid detection and response capabilities that can identify unusual access patterns early and contain a compromise before it spreads. The goal is to build layers of resilience so that even when an attacker gains access, the amount of data exposed and the resulting impact remain limited.”
Denis Calderone, COO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“Not to reduce the importance of the vulnerability that was exploited or the outsourced monitoring contract that failed to catch it, but what seems equally important here is why a road traffic agency was holding 18 years of payment data tied to national identification numbers for two-thirds of Latvia’s population. CSDD’s payment systems contained transaction records going back to 2008. Names, national ID numbers, home addresses, vehicle plates, payment amounts. For 1.2 million people in a country of 1.8 million. Latvia’s own accounting law requires a five-year retention period for source documents like payment receipts, not eighteen. You can’t steal data that’s already been deleted. If CSDD had enforced a reasonable retention policy and purged records older than five to seven years, the blast radius shrinks from a national-scale incident to something far more contained.
“This is the second time in a week we’re looking at a centralized government database holding national identification numbers for a significant portion of an entire country’s population getting compromised. Poland’s MyDr EMR breach affected 18.8 million PESEL numbers just days ago. Now Latvia’s CSDD exposed 1.2 million personal identification codes. Government systems accumulate decades of sensitive data because nobody builds the process to delete it when it’s no longer needed.
“Data minimization isn’t just a GDPR compliance checkbox. It is arguably the single most cost-effective breach-impact control available. CSDD was reportedly paying nine million euros over five years for IT infrastructure and round-the-clock monitoring from Tet. That monitoring failed to detect the attack. Several mandatory cybersecurity requirements hadn’t been met. But even if every one of those controls had worked perfectly, 18 years of sensitive data was still sitting in a system that didn’t need to hold it. The retention policy was the vulnerability.”
People who are victims of this hack had better be on the lookout for scams, phishing and the like headed their way as there is no good outcome for this.
Share this:
Like this:
Related
This entry was posted on August 20, 2026 at 8:00 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.