Security1 distinct publisher3 min readUpdated
An archive of payment receipts going back to 2008 at Latvia's CSDD exposed 1.2 million people and 200,000 businesses, and cost the agency's supervisory board its jobs.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Latvia's Road Traffic Safety Directorate said Tuesday that its investigation into a cyberattack found intruders had reached payment receipt data going back to 2008, exposing records on more than 1.2 million people and 200,000 businesses and other legal entities [1][2]. Latvia's population is just over 1.8 million, so the agency has confirmed a breach covering about two-thirds of the country [3][4]; by Wednesday morning its supervisory board had resigned and its chief said he would follow [13][14].
The technical story is unremarkable, which is the point. CERT.LV, the national response team, told public broadcaster LSM that the attackers exploited a vulnerability in a CSDD system exposed to the internet and that several mandatory cybersecurity requirements had not been met [10]. Varis Teivans, CERT.LV's deputy head, said the attack was targeted, prepared in advance, and showed technical competence [11]. None of that explains the size of the loss. CSDD registers vehicles and issues driver's licenses under the Transport Ministry [5]; the decision to keep the receipts from that work since 2008 is what turned one internet-facing service into a national register.
What was taken is durable: personal identification or company registration numbers, license plate numbers, payment amounts and dates, and addresses from vehicle registration certificates [6]. Phone numbers, email addresses, usernames and passwords were not compromised, and CSDD says some address records were incomplete [7]. That is a small mercy. Identity numbers and plate numbers do not rotate, and CERT.LV has warned the data can be used in social engineering and fraud schemes [9]. Counting the legal entities alongside the individuals puts roughly 1.4 million subjects in the file [21].
Detection was the second failure, and it is already a contract argument. CSDD chief Aivars Aksenoks, a former mayor of Riga, said the agency holds a five-year contract with the Latvian telecom and technology company Tet covering IT infrastructure maintenance and monitoring, including some firewall and incident-monitoring functions [14][15]. According to Aksenoks, Tet neither detected the intrusion nor alerted the agency, and CSDD employees found it themselves and stopped it within several hours [16]. Tet has pushed back against suggestions that responsibility can already be assigned [17].
Operationally the agency held together. Services remained available online and in person [8], the methods and channels used by the attackers were identified and blocked with the cybersecurity authorities [20], and a further attempt over the weekend was stopped after post-breach hardening [19]. CSDD has restricted the service that let users look up vehicle details from a license plate [18]. None of that protected the leadership. President Edgars Rinkevics called the attack a significant threat to national security and said public trust in the institution had been undermined to the point where its management must not continue [12]. The MP Andris Kulbergs called for the management and supervisory board to go; the board resigned the next morning [13]. Aksenoks said he was ready to leave but wanted to finish first: "I can't just slam the door behind me and leave" [14].
Watch which mandatory requirements CERT.LV found unmet, and whether that finding attaches to the agency or to its monitoring contractor [10][17]. Watch whether the plate-lookup restriction becomes permanent [18]. And watch whether any Latvian institution is asked the question the receipts pose: why 2008 data was still reachable from a production system at all.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Latvia's Road Traffic Safety Directorate (CSDD) said Tuesday that its investigation found hackers had accessed data from payment receipts dating back to 2008.
The breach affected records belonging to more than 1.2 million people and 200,000 businesses and other legal entities.
CSDD confirmed that hackers stole data connected to about two-thirds of the country's population.
CSDD is the state agency responsible for vehicle registration, driver's licenses and other road safety services, and operates under Latvia's Transport Ministry.
The stolen information includes personal identification numbers or company registration numbers, vehicle license plate numbers, payment amounts and dates, and addresses listed on vehicle registration certificates.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named-official statements, one publisher, no technical artifacts
Core facts come from the affected agency's own investigation statement, Latvia's national CERT, the president, a named MP, the agency head and the supplier's chairman - all attributed and specific. But the cluster contains a single publisher, no CVE or product identification for the exploited internet-exposed system, no independent forensic confirmation, and no evidence of the data itself surfacing. Scope and root cause therefore rest on assertions relayed by one outlet.
Consequences already realized, not prospective
This is not a technology-uptake story, but the real-world consequences are concrete and observable rather than anticipated: a confirmed breach of national-scale records, a supervisory board resignation and a departing agency head, a public service withdrawn, and a second intrusion attempt reportedly blocked after hardening. What is not yet observable is downstream fraud actually occurring or regulatory penalties landing.
Framing slightly outruns record-level precision
The reporting is restrained and largely quotes primary actors, but two framings run marginally ahead of the underlying data. 'Two-thirds of the country' is derived from record counts in a receipt archive spanning 18 years, which need not map one-to-one onto living residents, and the source itself notes address data was incomplete in some records and that credentials were untouched. The attacker-competence and 'complex attack' language is asserted without technical substantiation. Countervailing: no exaggerated attribution, no unsupported nation-state claim, and the agency's own limits on what was exposed are reported.
Active blame allocation between agency, supplier and politicians
Nearly every voice in the story has a declared stake in where responsibility lands. The agency head, while conceding he will leave, points at the outsourced monitoring provider; that provider's chairman insists responsibility cannot be assigned before the investigation completes and narrows its scope of duty; the president and an MP press publicly for resignations; and the national CERT's finding that mandatory requirements were unmet cuts against the agency. Read the causal claims as positional statements in a live liability contest.
Facts of impact solid, causation and liability open
High confidence that a large breach occurred, what fields were taken, that a public service was restricted and that the supervisory board resigned - these are on-record, specific and self-reported by the responsible parties. Lower confidence on causation, detection failure and eventual liability, given one publisher, no technical artifacts, an explicit dispute between agency and supplier, and investigations by data protection authorities and police still running.
product
France's tax agency lost 678,000 records through logins it had issued itself1 distinct publisher
security
One warehouse breach, two brands notifying: CEVA's retention clock set the blast radius1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026