Huge cyberattack affects two-thirds of country’s population: we talk to a victim
Typically, the agency that was targeted was late to report the attack.

Latvia has suffered a huge cyberattack. By Shutterstock / Cybernerws.
- A cyberattack on Latvia’s CSDD exposed personal data of about 1.2 million people.
- Stolen data includes ID numbers, names, addresses, license plates, vehicle details, and historical payment records.
- CSDD delayed notification beyond 72 hours, and its board and supervisory council resigned.
- Experts warn stolen data could fuel convincing scams; residents should verify urgent messages through official sites.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Around 1.8 million people live in Latvia, and approximately 1.2 million of them now have their personal data exposed after a massive cyberattack on the Baltic country’s Road Traffic Safety Directorate (CSDD). Speaking with Cybernews, one of the victims said she was worried – but not surprised.
The reason she’s not shocked about the huge breach – the second-largest incident of its kind in Latvia’s history – is probably because, in hindsight, it looks like the CSDD hadn’t been prepared for such an eventuality.
First, even though the cyberattack happened on August 8th or 9th, the agency only publicly revealed it on August 13th.
It then took another 4 days for the full scale of the breach to be officially disclosed, and only on August 27th were citizens finally able to individually check whether and what kind of their personal data was exposed.
“I will change all passwords”
Latvians are now asking why it has taken so long to inform the general public that their personal details have been stolen and might be misused.
All the addresses, my car plate numbers, personal code, some payment confirmations. It’s a lot, so I’m glad I have another bank account in another country. People in Latvia are going crazy,The victim of the breach told Cybernews.
“The way the authorities have been dealing with this is quite bad – nobody is taking responsibility. It’s always the same in Latvia.”
The woman, who is currently residing in another European country, told Cybernews she was probably going to join a class action lawsuit if it’s filed.
“I’m also about to change all my passwords just in case. The scariest part is that you just don’t know where that data has gone: I know all about phishing, but it’s a different story if someone tries to get into your bank account,” she said.
It’s been officially confirmed that an unknown – or unnamed – perpetrator swooped up personal ID numbers, names, some addresses, license plate numbers, vehicle details, and historical payment data from the CSDD systems.
Check if your data has been leaked
The CSDD has made it possible for customers to familiarize themselves with the personal datasets obtained by the attacker.
The agency has also urged people not to share the data publicly and warned the public that the stolen data can be used in further cyberattacks against individual citizens.
However, since the CSDD failed to notify the State Data Inspectorate and the cyber incident response agency “Cert.lv” within the timeframe of 72 hours, heads are rolling.
Heads had to roll
The CSDD officials seemed in no hurry to take responsibility for what had happened, but after Latvian President Edgars Rinkēvičs publicly said that the agency’s management cannot possibly continue working, the entire board and supervisory council stepped down.
“In the initial stage of the CSDD crisis, the management board, which later resigned, approached the situation with an attitude along the lines of: What’s the big deal? Losses are enormous,” Filips Rajevskis, a political scientist, told Baltic News Network.
“If an enemy uses this data, it can obtain an enormous amount of information about the people who live here, their daily routines, and their lives.”
State Police and the Prosecutor General's Office opened criminal investigations into the leak. It’s unclear which specific hacking collective is behind the breach, but most theories revolve around Russian involvement.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Security experts speculate that the targeted data could be highly valuable to a foreign intelligence agency, allowing it to track the physical movements, assets, and home addresses of senior Latvian officials, military personnel, and intelligence figures.
Smaller-scale criminality is a closer-to-home scenario, though, as cyber crooks could use the stolen data in social engineering and fraud schemes, said Lāsma Dilba, Deputy Director of the State Data Inspectorate.
“Residents whose data has been stolen should be very cautious, especially those whose information can be found in other public databases, such as declarations of public officials or land registers, as the greatest risk occurs when data is combined,” Dilba pointed out.
Researchers: always double-check
According to the Cybernews research team, the most immediate risks in this case include various types of scams via emails, phone calls, or text messages.
If a person suspects that their data could be among the leaked records, they should expect these kinds of attempts and for them to be pretty convincing, given that ID numbers and vehicle registration data were leaked as well,Cybernews researchers explained.
The golden rule is to never authenticate yourself via email, a phone call, or a text message. And if the message sounds particularly urgent, you should double-check it on the institution's official site.
“Additionally, don’t approve any MFA attempts that you haven’t initiated, for instance, a Smart-ID. Make sure your passwords are different, so that if credentials were stolen, they’d be isolated to one platform only,” the researchers point out.