Latvia's Road Traffic Safety Directorate, which handles vehicle registration and driver's licenses, announced a significant data breach affecting its systems. The breach affected records belonging to more than 1.2 million people and 200,000 businesses and other legal entities.
Cyberattack Details
The stolen information includes personal identification numbers or company registration numbers, vehicle license plate numbers, payment amounts and dates, as well as addresses listed on vehicle registration certificates. Customer phone numbers and email addresses were not affected, and address information was incomplete in some records.
Usernames and passwords were also not compromised. The agency said its day-to-day operations had not been disrupted, and both online and in-person services remained available.
Investigation and Response
Latvia's computer emergency response team (CERT.LV) warned that criminals could use the stolen information in social engineering and fraud schemes. The agency is still investigating the attack and working to identify those responsible.
The agency has also restricted access to a service that allows users to look up information about a vehicle, including its make and model, using its license plate number. The agency said it faced another attempted cyberattack over the weekend but was able to block it following security improvements introduced after the initial breach.
Complex Attack
CSDD first disclosed the breach last week, describing it as a “complex” cyberattack in which third parties gained partial access to systems containing historical payment receipt data. At the time, the agency said it had worked with cybersecurity authorities to identify and completely block the “methods and channels” used by the attackers.
“The information obtained so far indicates that the attack was targeted and that prior preparation was made for its implementation,” said Varis Teivans, deputy head of CERT.LV. “The nature of the attack and the set of methods used also indicate the technical competence of the attackers.”
Political Controversy
The incident has since escalated into a political controversy over responsibility for the attack. President Edgars Rinkevics said the attack posed “a significant threat to national security” and argued that CSDD’s leadership should step down.
“The CSDD's reputation and public trust in this institution have been undermined,” Rinkevics said in a post on X. “Under such circumstances, the CSDD management must not continue its work.”
Latvian member of Parliament Andris Kulbergs also called for CSDD’s management and supervisory board to resign. On Wednesday morning, the agency’s supervisory board submitted its resignation.
Resignations and Shifting Blame
CSDD chief Aivars Aksenoks, a former mayor of Riga, said he was also preparing to leave once he had helped complete the investigation and address the consequences of the attack. “I can't just slam the door behind me and leave,” Aksenoks told local media.
Aksenoks said responsibility for the breach may not lie with CSDD alone, pointing to Latvian telecom and technology company Tet, which provides some of the agency’s IT infrastructure and security monitoring.
Tet has pushed back against suggestions that responsibility can already be assigned, saying investigators first need to determine how and when the attackers gained access, which systems were compromised, and where security measures failed.
Source: The Record