Ransomware paralyzes Latvia’s state forestry systems

The physical heart of the industry remains, while the digital pulse goes dark.
Image composition · tobriefImagine needing a hunting permit, a forestry map, or timber delivery data and finding every system dark. On 22 June, a cyberattack struck Latvijas valsts meži (LVM), Latvia's state forestry company, knocking out about half its IT systems during the Jāņi midsummer holiday, when fewer staff were watching screens (LTV).
LVM pulled public services offline as a precaution: digital maps, the Mednis hunting app, and partner data exchanges. The company began restoring from backups and refused to cooperate with the attacker. Latvia's cyber-response team CERT.LV confirmed that stolen material had been published online, though investigators were still determining what data was actually taken. Their assessment: a commercially motivated ransom operation, not a state-linked campaign (LTV). A profit-seeking criminal crew shut down services citizens depend on daily.
Old Wiring Behind New Walls
Think of a large public organisation as a renovated building. The lobby looks modern: web portals, mobile apps, interactive maps. Behind the walls, old wiring remains. Sign-in systems that predate modern security protections. Contractors' remote connections nobody audited in years. These weak points are invisible to the public, but they are the first doors attackers try.
Ransomware gangs typically enter through a stolen password or an unpatched system, then quietly work to turn a low-level login into full administrator control, moving from room to room in the metaphorical building until they hold the master key. By the time anyone sees a ransom note, the intruder may have been inside for weeks (CISA). LTV reported that probing of LVM's security systems began before the visible attack date (LTV).
Public organisations are especially exposed. They cannot tolerate downtime, and they must keep old and new technology running together through long upgrade cycles (CISA, CrowdStrike). The seams between legacy and modern infrastructure are where security breaks.
The Pattern Next Door
Latvia's attack fits a wider problem in the region. In Lithuania, authorities have been investigating the theft of more than 600,000 Real Estate Register extracts, including personal identification codes, from state registry operator Registrų centras (LRT). The access path ran through stolen employee accounts, with the first illicit logins dating to early 2026. The public learned about it only months later (TV3). About 1,000 people were preparing to sue the state (Verslo žinios).
The two cases are technically different, but they expose the same gap: civilian digital systems that handle everyday public life, left under-defended. Germany showed where that gap leads. In 2021, the district of Anhalt-Bitterfeld declared a disaster after ransomware struck, with citizen services disrupted for weeks (Landkreis Anhalt-Bitterfeld).
The New Rules Meet a Real Outage
NIS2 is the EU directive that makes cyber resilience a board-level responsibility. Operators of essential services must send an early warning within 24 hours of detecting an incident, provide a detailed notification within 72 hours, and deliver a final report within one month (EUR-Lex). Senior management is personally accountable for cybersecurity risk (European Commission).
Latvia transposed NIS2 into national law effective September 2024, with minimum cybersecurity requirements entering force in July 2025 (Business.gov.lv). After the LVM attack, Latvia's acting prime minister signed five resolutions requiring ministries to report on state-system security and on how incident information flows through government (Kulbergs). He linked the incident to overdue cybersecurity regulations, acknowledging that written rules need operational follow-through.
The test now is practical, and it stretches well beyond the Baltics. How long will LVM's recovery take? Will citizens learn what personal data was exposed? Were backups actually tested before they were needed? Can a minister name who in their chain of command owns cyber risk for each public system? Every public operator in Europe faces these same questions. NIS2 ensures they can no longer go unanswered.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 6/26/2026, 3:29:59 AM
- Pipeline run:
- eu_pipeline_20260626_015006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication