Skip to main content
TECH_SCIENCE18 / 18 · scéal an lae3 nóim · 625 focal · 17 foinsí

LVM Hack Leaks 7,000 Passwords

Scríofa ag ISto brief AI · 4 Iúil 2026, 03:50
Conas a scríobhadh é

The data remains exposed long after the digital locks are changed.

Cumadóireacht íomhá · tobrief
an téacs · 3 nóim léitheoireachta

On 22 June, Latvia's state forestry company, LVM, did the thing every public operator hopes it will never have to do: it switched off its entire IT infrastructure to stop an attacker taking more files.

Wood deliveries to most buyers were moving again within four days. Most internal systems were back by 29 June. For an organisation that has to keep timber buyers supplied, contractors briefed and state assets managed, that was a quick recovery. But by then, about 44 GB of internal data had already appeared online, and the full haul may be larger.

LVM says it had working backups and received no ransom demand. Latvia's national cybersecurity authority, CERT.LV, confirmed the backups could be recovered, contradicting early reports that they had been destroyed. The company kept operating. The problem was what had left the system before the shutdown worked.

One old server, two weeks of access

Modern ransomware is less a padlock on a computer than a burglary carried out slowly. An intruder finds one weak door, moves through the building, gathers keys, copies papers and then threatens to publish unless paid. CISA's ransomware guide describes the usual sequence: get access, spread through the network, steal credentials, copy data and encrypt.

Cybersecurity expert Elvis Strazdiņš told Latvian media the attacker allegedly spent nearly two weeks inside LVM's systems, entering through a server running outdated software. The intruder reportedly accessed about 7,000 employee passwords and planted malware.

These are expert and press accounts, not official forensic findings. Still, they point to a familiar weakness for any large public-service operator, whether in Latvia or Ireland: a single unpatched server can undo a great deal of otherwise sensible security work.

Strazdiņš also said he contacted the hacker and was told the decryption price was about €618,600, calculated as 0.1% of LVM's revenue. LVM says no demand ever reached the company. CERT.LV chief Baiba Kaškina described the attacker as seeking fame more than money, noting that the group had hit organisations in several countries. There is no credible evidence of state sponsorship. The pattern looks like commercial ransomware with a taste for publicity.

Changed locks, photographed documents

LVM's backups saved its operations. They did not save the data that had already been copied.

That is the awkward half of a ransomware attack that often gets less attention. Backups can restore systems after encryption. They cannot unpublish passwords, security certificates or internal documents. A security certificate is a digital credential that proves a server is the server it claims to be. If that is compromised, trust in the system has to be rebuilt, not simply restored from storage.

Changing the locks after a break-in is necessary. It does not recover the papers photographed on the way out. CERT.LV warned that compromised passwords, certificates and digital keys all need to be replaced, and that leaked data creates continuing risks for any third party connected to LVM's systems.

When preparation becomes a legal question

That gap between "systems restored" and "data protected" is where the EU's NIS2 Directive comes in. NIS2 covers 18 critical sectors and changes the test for management. Leaders have to show they prepared for cyber risk before an attack, not just that they recovered afterwards. The directive makes senior leadership directly accountable for risk management and incident reporting.

Whether LVM sits fully inside NIS2 depends on how Latvia classifies it. Across the EU, full compliance timelines stretch into 2027 and beyond, which means many operators are still building the defences they will soon have to prove they had.

LVM's case shows both sides of that transition. The preparation that worked, including backups, staged restoration and continuity planning, got timber deliveries moving again within days. The preparation that failed, including keeping every server current and spotting an intruder sooner, left thousands of credentials and gigabytes of files exposed.

Kaškina put the imbalance plainly: defenders have to secure everything, while an attacker needs only one weak point. That is the daily problem for every European public-service operator, whether it manages forests, hospitals or supply chains.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
7/4/2026, 3:40:33 AM
Pipeline run:
eu_pipeline_20260704_015011
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology