Latvia CSDD payment-receipt data breach (2026)
incident · incident:latvia-csdd-breach-2026
Targeted intrusion into an internet-exposed system of Latvia's Road Traffic Safety Directorate between 8 and 10 August 2026, exfiltrating payment-receipt data dating to 2008 on 1.2 million individuals and 200,000 legal entities. Detected and stopped by the agency's own staff within hours; the outsourced provider contracted for round-the-clock monitoring neither detected nor reported it. The supervisory board resigned (CERT.LV, 2026-08-18; The Record, 2026-08-19).
Aliases: Ceļu satiksmes drošības direkcija cyberattack
Action items (1)
Do-now tasks recorded on the entries about Latvia CSDD payment-receipt data breach (2026), newest first. Check the date before acting on an older one.
- For every outsourced monitoring, SOC or MDR contract, establish on paper which systems and network segments the provider is actually obliged to watch, what it is obliged to alert on, and within what time, then test it with an authorised detection exercise inside a segment you believe is covered. The failure mode here was not an undetected technique but a boundary nobody had checked: the provider states its responsibility covered only certain parts of the infrastructure, not the whole network.2026-08-20CSDD's own staff found the intrusion and stopped it…
Defender insights
What each entry about Latvia CSDD payment-receipt data breach (2026) tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-20/latvia-csdd-breach-outsourced-monitoring-missed-it · ATT&CK page ↗
Entries about Latvia CSDD payment-receipt data breach (2026) (1)
Where this entity is cited
Source distribution
- cert.lv1 (33%)
- news.inbox.eu1 (33%)
- therecord.media1 (33%)
All cited sources (3)
- cert.lvCERT.LVhttps://cert.lv/lv/2026/08/csdd-saskaries-ar-kiberdrosibas-incidentu
- news.inbox.euinbox.euhttps://news.inbox.eu/150n4c8-why-tet-did-not-warn-csdd-about-the-cyberattack-the-company-commented-on-the-situation-for-the-first-time
- therecord.mediaThe Record (Recorded Future News)https://therecord.media/latvia-cyberattack-vehicle-data