Latvia CSDD Breach Exposes Data of 1.2M Citizens, Sparks Official Resignations
Latvia's Road Traffic Safety Directorate (CSDD) has confirmed that hackers stole personal and financial data tied to more than 1.2 million individuals and 200,000 businesses—roughly two-thirds of the country's 1.8 million population—in a targeted cyberattack that has triggered political fallout and calls for senior officials to step down. The agency disclosed that intruders accessed historical payment receipt records dating back to 2008, including personal identification numbers, company registration numbers, vehicle license plate numbers, payment amounts and dates, and incomplete address information from vehicle registration certificates. CSDD clarified that phone numbers, email addresses, usernames, and passwords were not affected, and that day-to-day operations and both online and in-person services remain functional.
According to CERT.LV deputy head Varis Teivans, the attack was deliberate and required significant prior preparation, with the hackers exploiting a vulnerability in an internet-exposed CSDD system. CERT.LV told Latvian public broadcaster LSM that several mandatory cybersecurity requirements had not been met by the agency. In response to the breach, CSDD restricted a public-facing license plate lookup service and has since blocked a second attempted attack over the weekend using security improvements implemented after the initial incident. The agency's computer emergency response team has warned that stolen personal data could fuel social engineering and fraud schemes targeting affected individuals.
The breach has escalated into a political crisis, with President Edgars Rinkevics publicly weighing in on responsibility for the security failure. The incident underscores the consequences of unpatched vulnerabilities in government systems handling sensitive citizen data. Organizations concerned about their own exposure can run a privacy checkup to identify potential leaks, while individuals should verify whether their personal information has appeared in known incidents using an email breach checker and update any reused credentials with a password checker to assess strength and uniqueness.