Security1 publisher3 min readPublished
Latvia's road agency kept payment receipts since 2008. The breach took two-thirds of the country
An archive of payment receipts going back to 2008 at Latvia's CSDD exposed 1.2 million people and 200,000 businesses, and cost the agency's supervisory board its jobs.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Latvia's Road Traffic Safety Directorate (CSDD) said Tuesday that its investigation found hackers had accessed data from payment receipts dating back to 2008.
- The breach affected records belonging to more than 1.2 million people and 200,000 businesses and other legal entities.
- Latvia has a population of just over 1.8 million.
- CSDD confirmed that hackers stole data connected to about two-thirds of the country's population.
- CSDD is the state agency responsible for vehicle registration, driver's licenses and other road safety services, and operates under Latvia's Transport Ministry.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Latvia's Road Traffic Safety Directorate said Tuesday that its investigation into a cyberattack found intruders had reached payment receipt data going back to 2008, exposing records on more than 1.2 million people and 200,000 businesses and other legal entities [1][2]. Latvia's population is just over 1.8 million, so the agency has confirmed a breach covering about two-thirds of the country [3][4]; by Wednesday morning its supervisory board had resigned and its chief said he would follow [13][14].
The technical story is unremarkable, which is the point. CERT.LV, the national response team, told public broadcaster LSM that the attackers exploited a vulnerability in a CSDD system exposed to the internet and that several mandatory cybersecurity requirements had not been met [10]. Varis Teivans, CERT.LV's deputy head, said the attack was targeted, prepared in advance, and showed technical competence [11]. None of that explains the size of the loss. CSDD registers vehicles and issues driver's licenses under the Transport Ministry [5]; the decision to keep the receipts from that work since 2008 is what turned one internet-facing service into a national register.
What was taken is durable: personal identification or company registration numbers, license plate numbers, payment amounts and dates, and addresses from vehicle registration certificates [6]. Phone numbers, email addresses, usernames and passwords were not compromised, and CSDD says some address records were incomplete [7]. That is a small mercy. Identity numbers and plate numbers do not rotate, and CERT.LV has warned the data can be used in social engineering and fraud schemes [9]. Counting the legal entities alongside the individuals puts roughly 1.4 million subjects in the file [21].
Detection was the second failure, and it is already a contract argument. CSDD chief Aivars Aksenoks, a former mayor of Riga, said the agency holds a five-year contract with the Latvian telecom and technology company Tet covering IT infrastructure maintenance and monitoring, including some firewall and incident-monitoring functions [14][15]. According to Aksenoks, Tet neither detected the intrusion nor alerted the agency, and CSDD employees found it themselves and stopped it within several hours [16]. Tet has pushed back against suggestions that responsibility can already be assigned [17].
Operationally the agency held together. Services remained available online and in person [8], the methods and channels used by the attackers were identified and blocked with the cybersecurity authorities [20], and a further attempt over the weekend was stopped after post-breach hardening [19]. CSDD has restricted the service that let users look up vehicle details from a license plate [18]. None of that protected the leadership. President Edgars Rinkevics called the attack a significant threat to national security and said public trust in the institution had been undermined to the point where its management must not continue [12]. The MP Andris Kulbergs called for the management and supervisory board to go; the board resigned the next morning [13]. Aksenoks said he was ready to leave but wanted to finish first: "I can't just slam the door behind me and leave" [14].
Watch which mandatory requirements CERT.LV found unmet, and whether that finding attaches to the agency or to its monitoring contractor [10][17]. Watch whether the plate-lookup restriction becomes permanent [18]. And watch whether any Latvian institution is asked the question the receipts pose: why 2008 data was still reachable from a production system at all.