Opens in a new tab

Commission finds CSDD cybersecurity gaps after August attack

Friday 18th September 2026 on 10:30 in Latvia

CSDD, cybersecurity, data protection

A commission established by Latvia’s Transport Ministry found several cybersecurity shortcomings at the Road Traffic Safety Directorate, including inadequate security testing, insufficient network protection and a lack of multifactor authentication, LSM reported, citing the ministry.

The commission said a vulnerability in CSDD’s web application med.csdd.lv enabled the attacker to initially access the organisation’s information systems. Technical and organisational shortcomings, including incomplete security testing, inadequate network protection, the absence of multifactor authentication and software development weaknesses, contributed to the vulnerability remaining unresolved.

The commission also identified the long-term storage of historical personal data. The Data State Inspectorate will assess that issue.

CSDD had a cybersecurity control system in place, but it repeatedly failed to achieve its purpose in practice. The commission found shortcomings in risk management and cybersecurity governance, including insufficient specialist capacity, security tests and audits with inadequate coverage, and incomplete documentation.

After gaining initial access, the attacker was able to obtain data over an extended period and on a large scale because CSDD lacked sufficient controls on the volume of requests and mechanisms to identify anomalies. The commission said a professional security monitoring service provider would normally be expected to identify and limit unusual, prolonged data activity in time to prevent extensive data extraction.

The cyberattack resulted in the personal data of 1.2 million people being obtained. CSDD fulfilled its legal reporting obligations to the competent state institutions within the required deadlines after detecting the incident.

The commission recommended that CSDD address the identified cybersecurity and data protection risks, assess data retention periods, ensure sufficient capacity for its cybersecurity function, and review and improve its contract with Tet.

Source 
(via LSM)