Opens in a new tab

Prosecutors open probe into attack on Interior Ministry system

Tuesday 29th September 2026 on 10:00 in Lithuania

cybersecurity, interior ministry, lithuania

Lithuanian law enforcement has opened a pre-trial investigation into last week’s cyberattack on the Ministry of the Interior’s information system, LRT reported. Prosecutor General’s Office spokeswoman Elena Martinonienė told news agency ELTA that the probe is being conducted under two Criminal Code provisions.

One provision covers the unlawful interception, acquisition, possession, disclosure or other use of non-public electronic data, and carries penalties of up to four years in prison. The other covers unauthorised access to an information system by circumventing its security measures, with a maximum prison sentence of two years.

The ministry said hackers broke into the EPEKIS system on Thursday evening. The system, administered by the Department of Information Technology and Communications, has not been actively used since 2018 and now serves as an archive of data on foreigners who have applied for Lithuanian citizenship.

Authorities blocked the unauthorised access. Hackers entered the system and created data sets, but investigators have not established that any data was downloaded. The ministry contacted the Lithuanian Criminal Police Bureau and the State Data Protection Inspectorate, and notified the National Cyber Security Centre.

Interior Minister Martynas Katelynas said the incident showed that Lithuania needed to strengthen its cybersecurity. He said security measures helped officials detect the intrusion quickly and prevent further malicious activity. Katelynas also said an artificial intelligence platform may have been used in the attack.

The Prosecutor General’s Office has been investigating a separate cyber incident since mid-April, in which more than 600,000 property records may have been stolen from the Centre of Registers. About 500,000 residents may have been affected, and the damage is estimated at no less than 111,000 euros. The data may have been accessed through Migration Department employees’ accounts. The first thefts were recorded in January, and the incident was publicly reported in late May.

Source 
(via LRT)