Hackers Steal Identity and Vehicle Data from Latvia’s Road Traffic Safety Directorate

Hackers Steal Identity, Vehicle Data from Latvia’s Road Traffic Safety Directorate

Hackers stole names, ID numbers, vehicle plates, addresses, and payment records belonging to 1.2 million people in Latvia’s CSDD data breach.

Listen to this article

0:00

Press play to start listening

Around 1.2 million people and 200,000 legal entities in Latvia have had data stolen after hackers breached a system operated by the Road Traffic Safety Directorate, known as CSDD. The number of affected people is roughly two-thirds of Latvia’s population.

The official CERT.LV notice says the attacker obtained the records between August 8 and 10. CSDD first acknowledged the incident on August 13, published the full data categories on August 18, and added a feature to its e-services portal, e.csdd.lv, on August 27. According to the agency, users who sign in can see whether their data was stolen and which personal details were exposed.

The stolen records came from historical payment receipts dating back to 2008. They included names, personal identity or company registration numbers, payment amounts and dates, vehicle registration plates, and addresses recorded when services were provided. CSDD said customer usernames, passwords, telephone numbers, and email addresses were not affected.

    System Flaws and Aftermath

    CERT.LV found that attackers exploited a vulnerability in an internet-facing CSDD system and that several mandatory cybersecurity requirements had not been met. De Facto reported that the initial entry occurred during the night of August 7 to 8 through CSDD’s Medical platform, which about 200 doctors use to submit medical certificates for drivers.

    Outgoing CSDD board chair Aivars Aksenoks said internal staff noticed suspicious activity from several IP addresses and blocked them within hours, although they did not immediately identify the data theft.

    Tet, the Latvian telecommunications and IT services company contracted to monitor parts of CSDD’s infrastructure, did not detect the activity. The company said CSDD managed the compromised application and that it fell outside Tet’s software and cybersecurity responsibilities under the contract.

    Latvian Television’s De Facto also reported that CSDD failed to notify Latvia’s State Data Inspectorate within the required 72 hours. President Edgars Rinkēvičs said the agency’s leadership could not continue under the circumstances.

    The supervisory board resigned first, and on August 19 Transport Minister Rihards Kozlovskis demanded the resignation of the executive board, which also stepped down that day.

    Latvian President Edgars Rinkēvičs responds to the CSDD data breach

    The CSDD incident occurred less than two months after ransomware hit Latvijas Valsts Meži, Latvia’s state-owned forestry company. The June breach disrupted its mapping platform, hunting application and several other systems, while about 44 GB of data was stolen. CERT.LV attributed it to a foreign, financially motivated ransomware group but did not name the group.

    Risks to Citizens

    Although passwords were not stolen, the exposed records can help scammers make messages or calls appear credible when impersonating CSDD or another organization.

    The risks also extend to law enforcement and national-security operations. Latvia’s State Police and National Armed Forces, along with other agencies involved in operational work, are assessing whether the registration plates on some service vehicles should be changed because the exposed records may identify vehicles used for sensitive activities.

    CSDD advises users to verify information directly through e.csdd.lv instead of following links in emails or text messages. CERT.LV also warns people not to approve Smart-ID or eParaksts authentication requests they did not initiate.

    (Photo by Olegs Jonins on Unsplash)

    Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Related Posts