ctipilot.ch

Latvia CSDD payment-receipt data breach (2026)

incident · incident:latvia-csdd-breach-2026

Targeted intrusion into an internet-exposed system of Latvia's Road Traffic Safety Directorate between 8 and 10 August 2026, exfiltrating payment-receipt data dating to 2008 on 1.2 million individuals and 200,000 legal entities. Detected and stopped by the agency's own staff within hours; the outsourced provider contracted for round-the-clock monitoring neither detected nor reported it. The supervisory board resigned (CERT.LV, 2026-08-18; The Record, 2026-08-19).

Aliases: Ceļu satiksmes drošības direkcija cyberattack

Coverage timeline
1
first 2026-08-20 → last 2026-08-20
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-20/latvia-csdd-breach-outsourced-monitoring-missed-it · ATT&CK page ↗

Story timeline

  1. 2026-08-20Latvia's vehicle-registration authority lost payment records on two-thirds of the country's population — and the provider contractually watching its infrastructure round the clock did not notice
    active-threatsCSDD's own staff found the intrusion and stopped it in hours; the outsourced monitoring never raised it, and the supervisory board has resigned

Where this entity is cited

  • active-threats1

Source distribution

  • cert.lv1 (33%)
  • news.inbox.eu1 (33%)
  • therecord.media1 (33%)

explore in graph

Entries about Latvia CSDD payment-receipt data breach (2026) (1)

2026-08-20 · view entry permalink →

HIGHNATOA1

Latvia's vehicle-registration authority lost payment records on two-thirds of the country's population — and the provider contractually watching its infrastructure round the clock did not notice

Latvia's Road Traffic Safety Directorate — CSDD, the state authority for vehicle registration and driver licensing — states that between 8 and 10 August 2026 inclusive an attacker obtained the data held in payment receipts going back to 2008, affecting 1.2 million natural persons and 200,000 legal entities (CERT.LV, 2026-08-18). Latvia's population is a little over 1.8 million, so that is roughly two-thirds of the country (The Record, 2026-08-19). What was taken is the combination that makes downstream fraud convincing rather than generic: personal identity code or company registration number, name, payment amount and date, vehicle licence-plate number, and the address registered at the time of the transaction. CSDD is explicit about what was not taken — customer contact details, meaning phone numbers and email addresses, were unaffected, the recovered address data is incomplete in some cases, and its earlier statement records that customer usernames and passwords were not compromised (CERT.LV, 2026-08-18).

The detection story is the part with a transferable lesson, and it runs the opposite way to the one an outsourcing arrangement is bought to produce. CSDD's own employees found the intrusion and stopped it within several hours; the agency's outsourced IT provider, Tet, did not detect it and did not alert the agency (The Record, 2026-08-19). The agency's chief describes the five-year contract as covering IT infrastructure maintenance and monitoring including some firewall and incident-monitoring functions (The Record, 2026-08-19), and as stipulating round-the-clock monitoring of the infrastructure (inbox.eu, 2026-08-19). Tet's own response is where the gap becomes legible: it says it is too early to draw conclusions about causes, states that its contractual responsibility extends only to certain parts of CSDD's IT infrastructure rather than the agency's whole network, has not disclosed how that scope was drawn, and confirms it engaged two subcontractors to fulfil the contract (inbox.eu, 2026-08-19). Nobody disputes that monitoring was contracted; what nobody had established, before it mattered, was the boundary of what "monitored" covered.

CERT.LV's own assessment is that the attack was targeted and preceded by preparation, and that the attackers showed technical competence; the entry point, per CERT.LV speaking to Latvian public broadcaster LSM, was a vulnerability in a CSDD system exposed to the internet, on which several mandatory cybersecurity requirements had not been met (The Record, 2026-08-19). No CVE, product or vendor has been named. CSDD also disclosed that it faced a further targeted attack the following weekend, which was blocked thanks to the security improvements made in the interim (CERT.LV, 2026-08-18) — a reminder that a disclosed public-sector breach draws follow-on attempts while remediation is still in flight. The institutional consequences have been fast: the supervisory board resigned on the Wednesday morning after calls to do so from the President and a member of parliament, and the agency's chief says he intends to resign once the investigation and its consequences are dealt with (The Record, 2026-08-19).

laika posmā no 2026. gada 8. līdz 10. augustam (ieskaitot) kiberuzbrucējs ir ieguvis informāciju par maksājumu kvītīs ietvertiem datiem laika periodā no 2008. gada. CSDD norāda, ka ietekmēti 1,2 miljonu fizisko personu un 200 tūkstošu juridisko personu dati.

CERT.LV 2026-08-18

He said Tet did not detect the intrusion or alert the agency. Instead, CSDD employees discovered the attack themselves and stopped it within several hours.

The Record (Recorded Future News) 2026-08-19
incident20 Aug 05:02Zmulti-sourceOpen finding ↗