Skip to content

Security3 publishers2 min readPublished

Latvian police trace two extortion breaches to one man running an automated scanner

Latvian police say one man with an automated scanner and an anonymous mailbox turned two mid-sized company websites into an extortion business. Investigators linked the two cases on similarities in the methods used.

The Watch · Security desk

Illustration accompanying Latvian police trace two extortion breaches to one man running an automated scanner

What happened

  • One attack took place in February; the second was detected in early September at TSC, the household appliance and smart device repair company inside telecoms group LMT.
  • Police said the suspect did not appear to pick his victims, and that automated tools were pointed at different websites and online resources to find vulnerabilities.
  • For most TSC customers, the repair-order records reached in the breach held names or company names, telephone numbers, email addresses and repair receipt numbers.
  • The search produced evidence of other alleged attacks on companies in Latvia and abroad, and those investigations are still open.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Some of the TSC records went further than contact details: device IMEI numbers, device access codes, bank account numbers and access codes for repair facilities. Whoever held the export had the handsets and the repair premises within reach.
  • capability One operator covered discovery, theft and the ransom demand, with no affiliate structure, no broker and no leak site. That puts the cost of extorting a mid-sized firm at the price of a scanner and an anonymising service.
  • constraint An automated scan picks victims by what it finds open. Small and obscure companies get selected alongside everyone else. That puts every internet-facing form and database on the list, including the ones a company has forgotten it runs.
  • precedent Latvia is running this as a five-year-maximum matter. That five-year maximum is the local sentencing frame for scan-and-extort work by a lone operator.

Once the scan flagged a vulnerability, the suspect reached the website's database and exported what it held, including restricted-access records, according to the State Police [6]. The location the activity came from was hidden behind what police called virtual camouflage tools [7]. The payment demand then arrived at the victim company from an anonymous email account [8].

The February case gave investigators a pattern, and the TSC intrusion detected in early September matched it. Police linked the two on similarities in the methods used [5], analysing the TSC incident with LMT Security Service and CERT.LV to establish a possible connection [9]. From the February detection to the arrest is about seven months [25].

TSC said the intruders exploited a vulnerability on its website to reach a database of customer repair orders [13]. Content stored on the devices customers had handed in was not affected [16]. The company suspended its website, brought in outside cybersecurity experts and kept repairs running through staffed customer service [17]. It has not said how many customers were affected or which vulnerability was exploited [23].

The State Police described the man as born in 2003 [1]. The Record reported him as 23 and said his identity has not been disclosed [2]. He is a suspect in both criminal proceedings, under Latvian provisions covering unauthorised access to automated data processing systems for financial purposes, extortion, and unlawful actions involving such systems [19]. Police said they have reason to believe their response stopped the stolen personal data from being passed to third parties [21], and noted that he is presumed innocent until guilt is established under the law [22].

TSC repairs smartphones, smart devices and household appliances in Latvia, Lithuania and Estonia [24]. The company said its IT systems run separately from the rest of the LMT group, and there is no indication that LMT's telecommunications network was compromised [18].

What to watch

  • Whether the evidence seized in Riga concerning companies in Latvia and abroad produces further charges or foreign requests.
  • Whether TSC identifies the vulnerability class or publishes a count of affected repair customers.
  • Whether CERT.LV reports the same scan-then-extort pattern against other Baltic mid-sized firms.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories