Skip to main content
TECH_SCIENCE04 / 05 · story of the day3 min · 710 words · 32 sources

Latvia’s 1.2 Million-Person Breach Fuels Scams

Written by AIto brief AI · 24 August 2026, 02:50
How it was written

Decades of ordinary transactions become a permanent catalogue for fraud.

Image composition · tobrief
the text · 3 min read

Someone who registered a car in Latvia any time since 2008 now has a problem. Attackers broke into the country's road-traffic authority, CSDD, and walked away with payment-receipt records tied to about 1.2 million people and roughly 150,000–200,000 companies (LSM, BNN). In a country of fewer than two million inhabitants, that covers most of the adult population. Nobody's bank account was drained. What criminals got instead is the raw material for convincing fraud, and it will not expire quickly, because the records stretch back nearly two decades.

What a scammer now knows

The stolen data reads like a personalised dossier. Names, national identity codes, vehicle registration plates, payment amounts, payment dates, and the home address on file when a service was used (tezinas.lv, inbox.lv). Phone numbers, email addresses, bank details and login credentials were not taken (NRA). That sounds reassuring until you picture the phone call: a voice cites your correct ID number, your car's plate, the exact fee you paid last year, and the address you lived at when you paid it. Most people would not hang up.

The ID code alone cannot unlock Latvia's digital identity tools, such as Smart-ID or Mobile-ID. But a scammer who knows your code can start a login attempt, triggering an approval prompt on your phone, then call pretending to be CSDD or your bank while you are staring at that prompt, pressuring you to tap "approve" (NRA). Scammers were already sending fake CSDD-branded emails and SMS within days of the disclosure (Delfi, tezinas.lv). The fraud window will not close quickly: records include people who registered a car in 2008 and have since left the country (LSM).

Basic locks were missing

The intrusion began over the weekend of 7–8 August. Latvia's national cyber-response body, CERT.LV, was notified only on Monday evening, 10 August (NRA). CSDD told the public on 13 August that its website had suffered an attack. The full scale reached the public only on 18 August (eng.lsm.lv, LSM).

What went wrong was not exotic. Latvian reporting found that CSDD had not met several requirements for systems classified at the highest sensitivity level, meaning systems that hold enough personal data to affect most of the population. Requirements like multi-factor authentication, needing both a password and a second confirmation to log in, were absent. So were penetration tests, paid attempts to break in before real attackers do (BauskasDzīve/LETA, Delfi).

CERT.LV had offered to install network-monitoring sensors, essentially smoke alarms for suspicious traffic, from January to April. The system was being set up only after the breach (LA.lv).

The political fallout was swift. President Edgars Rinkēvičs said CSDD's leadership should not remain in office and asked prosecutors to examine the case. Both the CSDD board and council resigned (Delfi, Kauno diena). A separate IT failure had already forced the closure of Latvia's Pāternieki border crossing with Belarus earlier this month, making the resilience of Latvian state IT systems a live political question even before CSDD's breach sharpened it.

A pattern, not an outlier

Latvia is not alone. Lithuania disclosed earlier this year that prosecutors believe more than 600,000 records were illegally copied from its national property and legal-entity registry, with unauthorised logins occurring through other institutions' connected systems (LRT). The attack route was different, the outcome familiar: stolen administrative data, delayed public clarity, and warnings that criminals would impersonate state agencies (LRT).

EU rules already treat both transport systems and public registries as critical infrastructure under NIS2, the bloc's updated cybersecurity directive. The law requires fast incident reporting and gives regulators enforcement powers (ENISA, The Record). But when the body that failed is a state agency rather than a private company, accountability tends to work through audits and political pressure rather than fines.

The CSDD breach did not require a sophisticated state-level operation. It required an internet-facing system where the basics were missing. Europe's digital government runs on interconnected registries holding decades of administrative data, and governments keep asking citizens to trust those registries with more. That trust now depends less on building shiny new digital services than on making boring controls, passwords, access logs, smoke-alarm sensors, work before someone tests them.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
8/24/2026, 1:53:45 AM
Pipeline run:
eu_pipeline_20260824_005006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology