CSDD says cyberattack exposed payment receipt data

Thursday 20th August 2026 on 12:45 in Latvia

CSDD, cyberattack, data security

The Road Traffic Safety Directorate, known as CSDD, said a cyberattack on its IT systems exposed some customer data contained in payment receipts, but not telephone numbers, email addresses, bank details or e-CSDD access information, LSM reported.

The attack on August 10 created an unauthorised opportunity for a third party to access information in CSDD systems, including personal data. The agency said the affected payment receipt data may include a person’s name and surname or a company name, a personal identity number or company registration number, the payment amount and date, a vehicle registration number, and the address registered on the day the service was received.

CSDD said customer telephone numbers, email addresses, bank details and e-CSDD access information were not affected.

The agency said customers can currently access CSDD e-services only through secure authentication solutions, including eID, eParaksts mobile, eID Scan, Smart-ID or internet banking.

CSDD is still analysing the scope of the affected data. Customers who have made a payment for CSDD services since 2008 may have had their personal data affected.

Customers can log in to e.csdd.lv and open the “Other payments” and “Payment history” sections to view payment deductions associated with them and the personal data shown in those records. CSDD said it was still determining the scope of the current personal data categories affected, as not all compromised data remains up to date.

The agency urged people to remain vigilant and follow cybersecurity specialists’ advice when using their personal data. CSDD warned that the data could be used for various fraudulent activities, including initiating authentication requests through electronic identification tools such as Smart-ID by using a personal identity number.

CSDD is cooperating with the State Police and has provided it with all available information about the cyberattack to help identify and prosecute those responsible. The agency said it had preserved all available information about the attack for submission to the Data State Inspectorate for a comprehensive review of the incident.

Source 
(via LSM)