Skip to main content
TECH_SCIENCE18 / 18 · story of the day3 min · 565 words · 17 sources

7,000 passwords leaked in LVM cyberattack

Written by AIto brief AI · 4 July 2026, 03:50
How it was written

The data remains exposed long after the digital locks are changed.

Image composition · tobrief
the text · 3 min read

On 22 June, Latvia's state-owned forestry company LVM shut down its entire IT infrastructure to stop an attacker from copying more files. Wood deliveries to most buyers resumed within four days, and most internal systems were back by 29 June. But roughly 44 GB of internal data had already been published online, and the total stolen may be larger.

For a state forestry operator, four days is fast. Buyers still need timber, contractors still need instructions, and a public company still has to function while investigators work. LVM says it had working backups and received no ransom demand. Latvia's national cybersecurity authority CERT.LV confirmed the backups were recoverable, contradicting early reports they had been destroyed. The organisation kept running. The problem is what left the building before the doors closed.

One old server, two weeks of access

Modern ransomware works less like a locked computer and more like a burglary. The intruder finds one weak entry, moves room to room collecting keys, copies papers, then threatens to publish unless paid. CISA's ransomware guide describes this standard progression: gain access, spread through the network, steal credentials, copy data, encrypt.

Cybersecurity expert Elvis Strazdiņš told Latvian media that the attacker allegedly spent nearly two weeks inside LVM's systems, entering through a server running outdated software. The intruder reportedly accessed roughly 7,000 employee passwords and planted malware. These are expert and media accounts, not official forensic findings. But they illustrate a well-established vulnerability: one unpatched server in an otherwise current network can open the whole estate.

Strazdiņš also said he contacted the hacker and was told the decryption price was about €618,600, pegged at 0.1% of LVM's revenue. LVM says no demand ever reached the company. CERT.LV chief Baiba Kaškina described the attacker as seeking fame more than money, noting the group had targeted organisations across multiple countries. There is no credible evidence of state sponsorship. The pattern fits commercially motivated ransomware with a side of publicity-seeking.

Changed locks, photographed documents

LVM's backups saved its operations. The harder problem is that backups solve the encryption half but cannot un-leak files. Passwords, security certificates (the digital credentials that prove a server is who it claims to be), internal documents: once copied, they stay exposed no matter how well the originals are restored.

Changing your locks after a break-in is essential, but it does not recover the documents the burglar photographed on the way out. CERT.LV warned that compromised passwords, certificates, and digital keys all need to be replaced, and that leaked data creates ongoing risks for any third party connected to LVM's systems.

When preparation becomes a legal question

This gap between "systems restored" and "data protected" sits at the centre of the EU's NIS2 Directive, which covers 18 critical sectors. NIS2's core shift is that managers must prove they prepared before an attack, not merely that they recovered after one. The directive holds leadership directly accountable for risk management and incident reporting.

Whether LVM falls squarely into NIS2's scope depends on how Latvia classifies it. Full compliance timelines across member states stretch into 2027 and beyond, meaning many operators are still building the defences they will soon be required to demonstrate.

LVM's experience captures both sides of that gap. The preparation that worked (backups, staged restoration, continuity planning) meant deliveries resumed in days. The preparation that didn't (keeping every server current, detecting an intruder sooner) left thousands of credentials and gigabytes of files in the open. Kaškina put the asymmetry simply: defenders must secure everything, while an attacker needs only one weak point. That remains the standing challenge for every European public-service operator, whether it manages forests, hospitals, or supply chains.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
7/4/2026, 3:40:33 AM
Pipeline run:
eu_pipeline_20260704_015011
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology