Data Breach Affects 1.2 Million Individuals in Latvia Due to CSDD Cyberattack
In a significant cybersecurity incident, approximately 1.2 million individuals and 200,000 legal entities in Latvia have had sensitive data compromised following a breach of the Road Traffic Safety Directorate, commonly referred to as CSDD. This staggering figure represents roughly two-thirds of the nation’s population.
According to a formal notification from the Latvian government’s cybersecurity response team, CERT.LV, the attackers accessed the data between August 8 and 10. CSDD first reported the incident publicly on August 13, and additional updates were communicated, including the full scope of the data compromised on August 18. A dedicated feature has been added to its e-services portal allowing users to log in and verify whether their personal information was affected.
The stolen data includes payment receipts dating back to 2008, detailing names, personal identification numbers, vehicle registration information, payment amounts, and the dates of transactions. However, CSDD confirmed that usernames, passwords, phone numbers, and email addresses remain secure and were not part of the breach.
Upon investigation, CERT.LV determined that the hackers exploited vulnerabilities within an internet-facing system of CSDD, exposing gaps in mandatory cybersecurity practices. Reports indicate that the initial access point was through CSDD’s Medical platform, utilized by approximately 200 healthcare professionals to submit driver medical certificates.
Despite observation of suspicious activities from several IP addresses by staff, the CSDD board did not associate these irregularities with data theft immediately. Furthermore, Tet, the telecommunications company responsible for monitoring certain aspects of CSDD’s infrastructure, stated that it was unaware of the breach, asserting that the relevant application was managed solely by CSDD.
Compounding the situation, CSDD reportedly failed to inform Latvia’s State Data Inspectorate of the breach within the legally mandated 72-hour period. In light of these failures, key leadership personnel have resigned, including the supervisory board, with the executive board following suit after pressure from the Transport Minister.
This incident follows a recent ransomware attack on Latvijas Valsts Meži, Latvia’s state-owned forestry enterprise, highlighting a worrying trend of cyber threats in the region. In that case, foreign cybercriminals were linked to the disruption of various systems and the theft of significant data.
Although there were no stolen passwords, the nature of the exposed data poses risks beyond mere identity theft; it could facilitate scams that mimic official communications from CSDD and other entities. Moreover, law enforcement in the country is grappling with the implications for national security, as the exposed records could identify vehicles involved in sensitive operations, prompting consideration for a review of license plates on certain service vehicles.
In light of this breach, CSDD is advising users to confirm any information via official channels rather than relying on potentially fraudulent communications. Cybersecurity authorities also urge caution against signing off on any unsolicited authentication requests.
Mitigating strategies should align with the MITRE ATT&CK framework, as relevant adversary tactics such as initial access through exploitation of public-facing applications and rapid lateral movement were evidently employed in this incident. The repercussions from this breach serve as a reminder of the pervasive risks in our increasingly digital landscape. Cybersecurity awareness and robust defense measures must continue to evolve to safeguard sensitive data and maintain public trust in governmental systems.