Tet says CSDD cyberattack came through agency app

Friday 21st August 2026 on 16:01 in Latvia

CSDD, cybersecurity, Tet

LSM reports that an internal investigation by technology company Tet found that the cyberattack on the Road Traffic Safety Directorate, or CSDD, was carried out through an application managed by the agency itself.

Tet said the application’s software and cybersecurity were outside the company’s responsibility under its contract with CSDD. The company’s experts have spent the past several days examining the circumstances of the data theft within the scope of that agreement.

Tet presented the initial findings to Economics Minister Viktors Valainis on August 21.

Under the contract, Tet manages CSDD’s network resources, connections and infrastructure and monitors data flows. However, it is not responsible for cybersecurity in services and applications developed by CSDD.

Tet said data-flow monitoring within its contractual responsibilities operated continuously, but the company could not detect the attack because the volume of data traffic is not, by itself, an indicator of a cyber incident.

The investigation also found that the contract did not give Tet access to the log files of CSDD’s med.csdd.lv application, which prevented the incident from being detected.

After reviewing Tet’s report, Valainis stressed the need to strengthen state institutions’ preparedness for cyber threats.

Tet executive Uldis Tatarčuks said the incident should lead to specific changes aimed at strengthening national cybersecurity and involving more industry professionals in protecting critical infrastructure.

“We understand people’s concern after this incident and recognise how important trust in the state’s digital services is,” Tatarčuks said. He added that Tet would continue sharing its expertise with CSDD and other state institutions to improve preparedness for cyber threats and help identify and prevent similar attacks in time.

Source 
(via LSM)