Data combining raises biggest risk after CSDD cyberattack
Friday 28th August 2026 on 07:15 in
Latvia
People whose personal data was stolen in a recent cyberattack on Latvia’s Road Traffic Safety Directorate, or CSDD, should be especially cautious because criminals could combine the information with data from other databases, State Data Inspectorate Deputy Director Lāsma Dilba told LSM’s Latvian Television programme Rīta panorāma.
The greatest risk applies to people whose information is also available in public databases, such as declarations by public officials or land registers. Combining the data could allow criminals to create highly detailed profiles and make their attacks more targeted, Dilba said.
She said the risks would remain for a long time. The incident was significant and affected fundamental rights, including the right to data protection, she added.
The State Data Inspectorate is assessing whether CSDD did everything required to protect the data. It cannot yet say whether CSDD committed a violation.
Under data protection rules, the data controller, which in this case is CSDD, must take all necessary technical and organisational measures to protect personal data. If the investigation finds that the measures were inadequate or insufficient, the inspectorate could establish that a violation occurred and consider corrective action.
Depending on the findings, negligence or improper actions by CSDD could lead to an administrative fine or another administrative measure. If CSDD is found to have taken all appropriate steps and the data was obtained through a particularly sophisticated and effective criminal attack, the assessment would be different, Dilba said.
She also noted that a personal identity code alone does not provide access to bank accounts or allow someone to act on another person’s behalf. However, it could be used to initiate fraud, including attempts by criminals to connect to a Smart-ID application.