Lithuanian bar association sees grounds for class action against registry centre over data breach
The mass theft of over 600,000 registry records from Lithuania’s Centre of Registers (RC) warrants a collective legal claim, with compensation for damages inevitable, the head of the Lithuanian Bar Association told LRT on Monday.
Mindaugas Kukaitis, chair of the association, argued that responsibility extends beyond the RC director to include government ministers and institutions whose access credentials were exploited. He suggested the breach may have targeted specific individuals—such as officials or public figures—based on their surnames or positions, leaving them vulnerable to blackmail or reputational harm.
Investigators confirmed last week that hundreds of thousands of records—including personal identification codes, property holdings, and transaction details—were stolen via compromised accounts at the Migration Department. Some data was accessed as early as January, though the RC reportedly became aware of the breach in April but disclosed it only on Friday.
Kukaitis stressed that the prolonged theft went undetected by state systems, calling it a systemic failure. “The Centre of Registers should have raised red flags when such volumes of data were accessed,” he said. “This isn’t just about one director’s accountability—it’s the state’s obligation to protect private data.”
He noted that while cyberattacks via malware are harder to trace, this breach involved authorised access abused for theft. “This wasn’t a random scrape of property records,” Kukaitis added. “Targeted data—like that of MPs—suggests deliberate selection, not indiscriminate collection.”
The Bar Association has long warned of foreign states seeking registry data, citing Ukraine’s experience. Kukaitis insisted compensation claims would serve as a “lesson in state accountability,” urging broader responsibility from ministers and law enforcement beyond the RC leadership, which saw its director resign following the disclosure.