More than 1,000 ask CSDD whether hackers accessed their data
Friday 21st August 2026 on 14:30 in
Latvia
More than 1,000 people have contacted Latvia’s Road Traffic Safety Directorate, or CSDD, to ask whether their data was affected by a recent large-scale cyberattack, LSM reported. CSDD says it can provide answers only in response to an electronically signed request.
CSDD representative Mārtiņš Mālmeisters told Latvian Radio that the request must be sent to the agency’s official email address. It must include the person’s full name, personal identification number and a question about their data in CSDD information systems. The request may be submitted as an officially electronically signed document or in a simplified format.
Mālmeisters said the agency cannot inform all affected people individually because the data of 1.2 million individuals was involved. An analysis is also still under way to determine which data dating back to 2008 is no longer current.
CSDD clients can check their payment history in the “Payment history” section of their eCSDD profile. The information includes payments for issuing and renewing driving licences, vehicle registration, vehicle technical inspections and other services. Mālmeisters said this was the information obtained by the hackers.
CSDD said the cyberattack affected the following personal data contained in payment receipts: a person’s name and surname or a company name; a personal identification number or company registration number; the payment amount; the payment date; the vehicle’s registration number; and the address registered when the service was received, such as the address listed on a vehicle registration certificate.
The agency said customers’ telephone numbers, email addresses, bank details and eCSDD access information were not affected.
In the first half of August, hackers gained unauthorised access to data on 1.2 million people and the registration numbers of about 150,000 legal entities through a cyberattack on CSDD’s information technology system. The data came from payments made to the agency over the previous 18 years. The cyber incident response institution Cert.lv said the attack exploited a vulnerability in a CSDD system accessible via the internet.