Latvia’s Road Traffic Agency Breach Exposes Data of 1.2 Million, Sparks Resignations

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a significant data breach affecting approximately 1.2 million individuals and 200,000 businesses, representing about two-thirds of the country’s population. The breach, which has led to calls for the resignation of senior officials, involved unauthorized access to historical payment receipt data dating back to 2008. The agency operates under Latvia’s Transport Ministry and is responsible for vehicle registration and driver’s licenses.

According to reporting by The Record, the stolen data includes personal identification numbers, vehicle license plate numbers, payment amounts, and addresses from vehicle registration certificates. However, customer phone numbers and email addresses were reportedly not compromised, and usernames and passwords remained secure.

Investigation and Political Fallout

The CSDD has stated that its daily operations have not been disrupted and that both online and in-person services continue to function. However, Latvia’s computer emergency response team (CERT.LV) has warned that the stolen information could be exploited for social engineering and fraud schemes. The agency is currently investigating the breach and has restricted access to certain services while enhancing security measures.

President Edgars Rinkevics has described the attack as a “significant threat to national security,” urging for the resignation of CSDD leadership. Following these statements, the agency’s supervisory board submitted its resignation, and CSDD chief Aivars Aksenoks indicated he would also step down after assisting with the investigation.

Technical Details and Responsibility

The breach has been characterized as a “complex” cyberattack, with CERT.LV noting that attackers exploited a vulnerability in a CSDD system that was exposed to the internet. Aksenoks has suggested that the responsibility for the breach may not rest solely with CSDD, pointing to the Latvian telecom and technology company Tet, which manages some of the agency’s IT infrastructure. Tet has denied responsibility, stating that it is only accountable for certain parts of the CSDD’s IT systems.

As investigations continue, Latvian cybersecurity and data protection authorities, along with state police, have opened criminal proceedings related to the incident. This breach follows another significant cyberattack earlier this summer against a state-owned forestry company, highlighting ongoing cybersecurity challenges within the country.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

NASA’s subscale flight lab supports advanced aerospace research and testing

NASA's Dale Reed Subscale Flight Research Laboratory at the Armstrong Flight Research Center in Edwards, California, is advancing aerospace research through innovative testing methods....

Flock’s Manufacturing Origins Under Scrutiny Amid Growing Backlash Against Surveillance Technology

Flock, a company known for its license plate cameras, is facing scrutiny over the origins of its manufacturing amid a growing backlash against surveillance...

AMOS Stealer Malware Targets macOS Users Through Malicious Toolkit Installations

Executive Summary Recent research has highlighted the emergence of AMOS stealer malware, which specifically targets macOS systems. This malware, first advertised on Telegram in April...

Infoblox Research Reveals 1.7 Million Chinese Casino Domains Linked to Cybercrime and Fraud

Infoblox Threat Intel has uncovered a staggering 1.7 million Chinese-language casino domains that are linked to various forms of cybercrime, including illegal gambling and...