LVM left vulnerability unpatched after misunderstanding warning
Sunday 16th August 2026 on 21:30 in
Latvia
Latvia’s state forest company Latvijas Valsts meži likely would have blocked the cyberattack if it had occurred two weeks later, the company told LSM’s investigative programme De Facto. However, the company had already been warned about the vulnerability by Latvia’s cyber incident response institution Cert.lv two years earlier.
The attacker, or group, using the alias ByteToBreach entered LVM’s GeoServer system on June 11. LVM uses the system to process geospatial data. The attacker then explored the company’s internal systems and gained deeper access.
The active attack began on June 22 and included encrypting and stealing data. The attacker later disclosed details of the intrusion in a public post, mocking LVM’s cybersecurity resilience.
LVM’s IT Infrastructure and Development Director Māris Kuzmins said the vulnerability had not been fixed because of a communication misunderstanding between the company and Cert.lv.
“Yes, it should have been fixed. What happened in our communication with Cert was a misunderstanding: we did not correctly understand the information and did not realise that the version in our possession was vulnerable,” Kuzmins said.
He added that LVM would have preferred somewhat different communication from Cert.lv, but acknowledged that the failure was on LVM’s side because the information had been misunderstood.
The data leak could potentially have affected several holders of critical infrastructure, underscoring the need to review IT system risks more broadly, De Facto reported.