Consumer watchdog reports contact data incident in information system

Thursday 3rd September 2026 on 08:00 in Latvia

consumer protection, cybersecurity, data security

Latvia’s Consumer Rights Protection Centre has detected a data security incident in one of its information systems, LSM reported, citing the centre.

An investigation so far indicates that contact information was retrieved from the Remote Statistical Data Retrieval System, known as ASDIS. The information concerned entities licensed by the centre, including consumer lending providers, out-of-court debt collection providers and package travel providers.

The retrieved data included the names, email addresses and telephone numbers of 697 company representatives and 34 officials of the Consumer Rights Protection Centre.

In most cases, the information is already available in other public registers, including Latvia’s Open Data Portal. The incident did not compromise supervisory data submitted to the centre by companies.

ASDIS is a Class C security system, the lowest risk level for information systems. The centre uses it to supervise licensed companies, and it meets Latvia’s minimum cybersecurity requirements.

The system is hosted on network infrastructure equipped with Cert.lv’s Early Warning Sensor system.

The affected system has now been shut down, and all users were immediately informed that it was unavailable.

The centre said that, amid an unstable geopolitical situation, it was important to strengthen the security of all technological resources and provide the necessary funding. The Ministry of Economics has previously made a similar point at a Cabinet meeting on cybersecurity issues.

Source 
(via LSM)