CSDD still assessing data stolen in cyberattack
Monday 17th August 2026 on 16:45 in
Latvia
Latvia’s Road Traffic Safety Directorate (CSDD) is still determining how much data attackers took and how many people’s personal information was accessed, LSM reported a week after the cyberattack.
The stolen information consists of historical payment receipt data for CSDD services. The records contain customers’ names, vehicle registration numbers, company names and registration numbers, addresses, payment dates and other information.
The data covers payments made since 2008. CSDD said it could not yet give an exact number of unique customers affected because the number of receipts is very large and customers may appear more than once.
CSDD said it had taken all necessary steps to protect its information technology systems from further attempts to breach them. Its representative Mārtiņš Mālmeisters said specialists were closely monitoring activity in the systems and fixing or improving any weaknesses they identified.
Customers do not need to take any additional action because usernames and passwords were not taken from the IT system, CSDD said.
However, Latvia’s cyberincident prevention institution CERT.lv warned that the stolen information could be used to create convincing and personalised fraud attempts. It urged people not to approve unsolicited requests through Smart-ID or eParaksts mobile. Personal identification numbers are of particular concern because people often use them as usernames when authenticating with these services for digital platforms such as Latvija.gov.lv or e-CSDD.