Two-factor authentication to launch at Lithuania’s Centre of Registers on Friday

Thursday 28th May 2026 on 10:30 in Lithuania Lithuania

cybersecurity, data breach, lithuania

Lithuania’s Centre of Registers (RC) will introduce mandatory two-factor authentication from Friday as part of strengthened cybersecurity measures following a major data breach, Economy and Innovation Minister Edvinas Grikšas announced on Thursday, LRT reports.

The system has been developed and tested, the minister told Žinių Radijas, adding that a competition to select a new director for the state-owned enterprise will also be launched on the same day.

Grikšas criticised the centre for failing to implement two-factor authentication earlier, which could have prevented unauthorised access even if third-party systems—such as those of the Migration Department—were compromised. “It is incomprehensible to me that the Centre of Registers did not have solutions that could have blocked access to the registers, even through breached external systems,” he said.

The data leak, first detected in early April, involved over 600,000 real estate registry records accessed via hacked Migration Department accounts, with estimated damages exceeding €111,000. While the centre initially reported only a few cases to the ministry, the full scale—affecting hundreds of thousands of records—was disclosed on April 21.

Grikšas confirmed that the Centre of Registers’ own systems were not directly breached. “The RC systems were not hacked. The attack targeted the Migration Department’s systems,” he stated, echoing earlier findings by Lithuania’s Criminal Police Bureau.

The minister acknowledged that the incident has undermined public trust in state institutions. “Every data leak, every cyberattack erodes confidence in government bodies and in the state itself. Such cases must not be repeated,” he said.

A pre-trial investigation into the breach was launched by the Prosecutor General’s Office last week.

Source 
(via LRT)