7,000 passwords leaked in LVM cyberattack

The data remains exposed long after the digital locks are changed.
Image composition · tobriefOn 22 June, Latvia's state-owned forestry company LVM shut down its entire IT infrastructure to stop an attacker from copying more files. Wood deliveries to most buyers resumed within four days, and most internal systems were back by 29 June. But roughly 44 GB of internal data had already been published online, and the total stolen may be larger.
For a state forestry operator, four days is fast. Buyers still need timber, contractors still need instructions, and a public company still has to function while investigators work. LVM says it had working backups and received no ransom demand. Latvia's national cybersecurity authority CERT.LV confirmed the backups were recoverable, contradicting early reports they had been destroyed. The organisation kept running. The problem is what left the building before the doors closed.
One old server, two weeks of access
Modern ransomware works less like a locked computer and more like a burglary. The intruder finds one weak entry, moves room to room collecting keys, copies papers, then threatens to publish unless paid. CISA's ransomware guide describes this standard progression: gain access, spread through the network, steal credentials, copy data, encrypt.
Cybersecurity expert Elvis Strazdiņš told Latvian media that the attacker allegedly spent nearly two weeks inside LVM's systems, entering through a server running outdated software. The intruder reportedly accessed roughly 7,000 employee passwords and planted malware. These are expert and media accounts, not official forensic findings. But they illustrate a well-established vulnerability: one unpatched server in an otherwise current network can open the whole estate.
Strazdiņš also said he contacted the hacker and was told the decryption price was about €618,600, pegged at 0.1% of LVM's revenue. LVM says no demand ever reached the company. CERT.LV chief Baiba Kaškina described the attacker as seeking fame more than money, noting the group had targeted organisations across multiple countries. There is no credible evidence of state sponsorship. The pattern fits commercially motivated ransomware with a side of publicity-seeking.
Changed locks, photographed documents
LVM's backups saved its operations. The harder problem is that backups solve the encryption half but cannot un-leak files. Passwords, security certificates (the digital credentials that prove a server is who it claims to be), internal documents: once copied, they stay exposed no matter how well the originals are restored.
Changing your locks after a break-in is essential, but it does not recover the documents the burglar photographed on the way out. CERT.LV warned that compromised passwords, certificates, and digital keys all need to be replaced, and that leaked data creates ongoing risks for any third party connected to LVM's systems.
When preparation becomes a legal question
This gap between "systems restored" and "data protected" sits at the centre of the EU's NIS2 Directive, which covers 18 critical sectors. NIS2's core shift is that managers must prove they prepared before an attack, not merely that they recovered after one. The directive holds leadership directly accountable for risk management and incident reporting.
Whether LVM falls squarely into NIS2's scope depends on how Latvia classifies it. Full compliance timelines across member states stretch into 2027 and beyond, meaning many operators are still building the defences they will soon be required to demonstrate.
LVM's experience captures both sides of that gap. The preparation that worked (backups, staged restoration, continuity planning) meant deliveries resumed in days. The preparation that didn't (keeping every server current, detecting an intruder sooner) left thousands of credentials and gigabytes of files in the open. Kaškina put the asymmetry simply: defenders must secure everything, while an attacker needs only one weak point. That remains the standing challenge for every European public-service operator, whether it manages forests, hospitals, or supply chains.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/4/2026, 3:40:33 AM
- Pipeline run:
- eu_pipeline_20260704_015011
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication