CSDD hacker likely targeted other state systems
Sunday 23rd August 2026 on 19:45 in
Latvia
The hacker who accessed the database of Latvia’s Road Traffic Safety Directorate, or CSDD, likely tried to penetrate other state systems, LSM reported, citing Latvia’s public television programme De facto. The conclusion was based on the methods used and the timing of the attack, according to Cert.lv, the institution responsible for preventing cyber incidents.
Data on 1.2 million individuals and 200,000 legal entities was stolen from the CSDD database, making it the second-largest data breach in Latvia’s history.
The attacker gained access to the CSDD Medical platform. The system had not undergone adequate penetration testing, and the breach took place during the night of August 7 to 8. It was not detected promptly, while Cert.lv was informed only on the evening of August 10.
CSDD also failed to notify Latvia’s Data State Inspectorate of the data breach within the legally required 72-hour period. The inspectorate is investigating the directorate’s actions.
Latvia’s State Police launched an inquiry on its own initiative and later opened criminal proceedings. Police are also monitoring whether the stolen data appears on the black market.
The CSDD board resigned following the incident. Later, the transport minister also demanded the resignation of the CSDD management board, which subsequently stepped down.
At the beginning of the year, Cert.lv offered CSDD state-funded services to help detect cyber incidents at an early stage.
De facto reported that CSDD officials had been slow to accept responsibility for the breach, raising the possibility that the directorate initially sought to keep the incident as quiet as possible. On August 18, CSDD board chairman Aivars Aksenoks appeared at an event to promote seat-belt use, while two board members and the head of the IT department attended an emergency government meeting on the theft of the personal and legal-entity data.