CSDD blocks cyberattack after historical payment data accessed

Thursday 13th August 2026 on 13:01 in Latvia

CSDD, cybersecurity, latvia

Latvia’s Road Traffic Safety Directorate (CSDD) was hit by a cyberattack over the weekend, with attackers gaining partial access to its IT system and unlawfully retrieving historical payment receipt data for CSDD services, LSM reports. The data did not include customers’ usernames or passwords.

The historical receipt data includes some personal information: personal identification or registration numbers, names or company names, payments, payment dates, vehicle registration numbers and addresses.

CSDD said it stopped the attack in cooperation with CERT.LV, Latvia’s cyber-incident response institution. It has made several improvements to the security of its IT systems to prevent similar attacks.

“The methods and channels used by the attackers have been identified and fully blocked,” said Māris Puriņš, head of CSDD’s IT department. He said the organisation would continue working closely with CERT.LV to assess the consequences of the attack.

“Customers’ usernames and passwords have not been affected, so no additional action is required from customers,” Puriņš said. CSDD urged the public to remain cautious and verify information through e.csdd.lv.

Varis Teivāns, deputy head of CERT.LV, said the investigation was continuing and the circumstances of the attack were still being clarified. Information gathered so far indicates that the attack was targeted and preceded by preparation, he said.

Teivāns said the nature of the attack and the methods used indicated that the attackers had technical expertise. He warned that the data obtained could be used in targeted fraud attempts.

Residents should be particularly cautious about emails, text messages and other communications that appear to have been sent on behalf of CSDD, Teivāns said. He advised checking whether such messages were genuine and verifying information through e.csdd.lv.

The incident has not affected CSDD’s in-person or online services, which continue to operate normally. CSDD has informed other competent state institutions, including the Data State Inspectorate, as it works to address the consequences of the attack.

Source 
(via LSM)