No evidence hackers have used CSDD data, cybersecurity centre says
Friday 14th August 2026 on 06:30 in
Latvia
There are currently no indications that personal data obtained in a cyberattack on Latvia’s Road Traffic Safety Directorate, known as CSDD, has been used, LSM reports.
Varis Teivāns, deputy head of the Cybersecurity Centre Cert.lv, told Latvian Television’s Rīta panorāma programme that the amount of data obtained in the attack was large and was still being determined.
The attackers may have been financially motivated, Teivāns said, although their motive remains unknown. He warned that the stolen personal identity numbers could potentially be used to try to access other systems where such numbers serve as identifiers.
In such cases, people could receive an authentication approval request on their smartphones. Teivāns urged people not to approve such requests unless they had initiated them themselves.
He said the attack was planned rather than random. The investigation will determine how it was carried out and what weakness in the system was exploited.
In early August, hackers gained unauthorised access to historical payment receipt data for CSDD services. The data included some personal information, such as personal identity or registration numbers, names or company names, payment details, payment dates, vehicle registration numbers and addresses.
The attack has been stopped and several improvements have been made to strengthen the IT system’s security. Customer usernames and passwords were not affected, and no additional action is required from customers. The incident has not disrupted CSDD’s in-person or online services, which continue to operate as usual.