2026-08-20 · view entry permalink →
Latvia's vehicle-registration authority lost payment records on two-thirds of the country's population — and the provider contractually watching its infrastructure round the clock did not notice
Latvia's Road Traffic Safety Directorate — CSDD, the state authority for vehicle registration and driver licensing — states that between 8 and 10 August 2026 inclusive an attacker obtained the data held in payment receipts going back to 2008, affecting 1.2 million natural persons and 200,000 legal entities (CERT.LV, 2026-08-18). Latvia's population is a little over 1.8 million, so that is roughly two-thirds of the country (The Record, 2026-08-19). What was taken is the combination that makes downstream fraud convincing rather than generic: personal identity code or company registration number, name, payment amount and date, vehicle licence-plate number, and the address registered at the time of the transaction. CSDD is explicit about what was not taken — customer contact details, meaning phone numbers and email addresses, were unaffected, the recovered address data is incomplete in some cases, and its earlier statement records that customer usernames and passwords were not compromised (CERT.LV, 2026-08-18).
The detection story is the part with a transferable lesson, and it runs the opposite way to the one an outsourcing arrangement is bought to produce. CSDD's own employees found the intrusion and stopped it within several hours; the agency's outsourced IT provider, Tet, did not detect it and did not alert the agency (The Record, 2026-08-19). The agency's chief describes the five-year contract as covering IT infrastructure maintenance and monitoring including some firewall and incident-monitoring functions (The Record, 2026-08-19), and as stipulating round-the-clock monitoring of the infrastructure (inbox.eu, 2026-08-19). Tet's own response is where the gap becomes legible: it says it is too early to draw conclusions about causes, states that its contractual responsibility extends only to certain parts of CSDD's IT infrastructure rather than the agency's whole network, has not disclosed how that scope was drawn, and confirms it engaged two subcontractors to fulfil the contract (inbox.eu, 2026-08-19). Nobody disputes that monitoring was contracted; what nobody had established, before it mattered, was the boundary of what "monitored" covered.
CERT.LV's own assessment is that the attack was targeted and preceded by preparation, and that the attackers showed technical competence; the entry point, per CERT.LV speaking to Latvian public broadcaster LSM, was a vulnerability in a CSDD system exposed to the internet, on which several mandatory cybersecurity requirements had not been met (The Record, 2026-08-19). No CVE, product or vendor has been named. CSDD also disclosed that it faced a further targeted attack the following weekend, which was blocked thanks to the security improvements made in the interim (CERT.LV, 2026-08-18) — a reminder that a disclosed public-sector breach draws follow-on attempts while remediation is still in flight. The institutional consequences have been fast: the supervisory board resigned on the Wednesday morning after calls to do so from the President and a member of parliament, and the agency's chief says he intends to resign once the investigation and its consequences are dealt with (The Record, 2026-08-19).
laika posmā no 2026. gada 8. līdz 10. augustam (ieskaitot) kiberuzbrucējs ir ieguvis informāciju par maksājumu kvītīs ietvertiem datiem laika periodā no 2008. gada. CSDD norāda, ka ietekmēti 1,2 miljonu fizisko personu un 200 tūkstošu juridisko personu dati.
He said Tet did not detect the intrusion or alert the agency. Instead, CSDD employees discovered the attack themselves and stopped it within several hours.