Cyberattack accesses data of 7% of TSC customers

Friday 11th September 2026 on 19:15 in Latvia

cybersecurity, data breach, TSC

A cyberattack on TSC, a company that repairs household appliances and smart devices and belongs to the Latvian Mobile Telephone LMT group, resulted in unauthorised access to data belonging to about 7% of its customers, LSM reported. The attack targeted the company website, which customers used to submit devices for repair. LMT databases were not affected.

The attackers gained access to part of the information stored in the website’s database. An initial investigation indicates that fewer than one in 10 TSC customers were affected. The company has not disclosed the number of customers whose names, email addresses and telephone numbers may have been obtained, citing the investigation.

TSC acted immediately to stop the attack and temporarily shut down its website for security reasons. The website has since resumed operation. TSC chief executive Jānis Ducmanis said customers could contact the company through its website, while compensation would be considered on a case by case basis.

Cybersecurity company Cert.lv said TSC was not a critical infrastructure company. It said there was no information about the attacker. Cert.lv cybersecurity expert Kārlis Svilāns said the incident showed similarities with attacks in which systems automatically scan for vulnerable fields, highlighting the need to identify all externally accessible resources and respond quickly.

TSC said its cybersecurity team had conducted an in depth security audit of the website’s source code and fixed the vulnerabilities identified. The company also introduced new web protection mechanisms with improved detection of suspicious activity and reviewed the database structure to further reduce the amount of customer data stored.

Customers have been advised to be cautious of unexpected or suspicious emails, text messages and calls, particularly those demanding urgent action or information. They should not disclose passwords, access details, payment information or authentication codes.

Source 
(via LSM)