Latvia’s Road Traffic Safety Directorate (CSDD) confirmed that attackers stole historical payment receipt data affecting more than 1.2 million people and 200,000 businesses and legal entities, making it one of the country’s largest reported public-sector data breaches. Exposed records reportedly included personal or company identification numbers, vehicle license plate numbers, payment amounts and dates, names, and some registered address information tied to service interactions, while officials said usernames, passwords, phone numbers, and email addresses were not compromised.
Latvian authorities said the intrusion was a targeted, technically sophisticated attack that exploited an internet-exposed vulnerability in a CSDD system, and CERT.LV indicated mandatory cybersecurity requirements had not been fully met. The breach prompted criminal proceedings, investigations by cybersecurity and data protection authorities, and sharp political fallout: President Edgars Rinkevics and lawmakers called for accountability, CSDD’s supervisory board resigned, and agency chief Aivars Aksenoks said he would step down after response work concludes. Prime Minister Andris Kulbergs described the incident as a national security issue, said foreign involvement could not be ruled out, and criticized delays in notifying the government.

See attribution, scope, and your downstream exposure.
9 events from the most recent confirmed update back to the earliest known activity.
Prime Minister Andris Kulbergs referenced another serious cyber incident affecting the state forestry administration in June 2026, using it to highlight broader cybersecurity weaknesses in government authorities.
CSDD said the stolen historical payment receipt data dated back to 2008, establishing the earliest known period covered by the compromised records.
Latvian state police opened criminal proceedings while cybersecurity and data protection authorities continued investigating the incident and trying to identify the perpetrators.
CSDD's supervisory board submitted its resignation on Wednesday morning amid political fallout from the breach and calls for leadership accountability.
President Edgars Rinkevics said the attack posed a significant threat to national security and called for CSDD leadership to step down. Prime Minister Andris Kulbergs said a foreign origin could not be ruled out, described the breach as a national security issue, and criticized delayed notification and weak cybersecurity practices.
CSDD said it stopped another attempted cyberattack over the weekend after implementing security improvements following the initial breach.
After the breach, CSDD said it worked with cybersecurity authorities to identify and completely block the attackers' methods and channels. It also restricted access to a vehicle lookup service that allowed users to retrieve vehicle information by license plate number.
CERT.LV said the attackers exploited a vulnerability in an internet-exposed CSDD system and described the operation as targeted, prepared in advance, and technically sophisticated. CERT.LV also said several mandatory cybersecurity requirements had not been met.
CSDD first disclosed the previous week that it had suffered a complex cyberattack involving partial access to systems containing historical payment receipt data. The breach affected more than 1.2 million people and 200,000 businesses and legal entities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcetherecord.media
Open sourcedailysabah.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.