Latvia Breach Opens Door to Scams

Decades of ordinary transactions become a permanent catalogue for fraud.
Cumadóireacht íomhá · tobriefAnyone who has registered a car in Latvia since 2008 now has a problem that may follow them for years. Attackers got into the country’s road-traffic authority, CSDD, and took payment-receipt records linked to about 1.2 million people and roughly 150,000–200,000 companies (LSM, BNN). In a country of fewer than two million people, that means much of the adult population is now exposed. The attackers did not empty bank accounts. They took something more durable: the details that make fraud sound believable.
What a scammer now knows
The stolen material is the kind of administrative data people rarely think about until it is gone. It includes names, national identity codes, vehicle registration plates, payment amounts, payment dates and the home address held on file when a service was used (tezinas.lv, inbox.lv). Phone numbers, email addresses, bank details and login credentials were not taken (NRA). That is some comfort, but only up to a point. If a caller knows your ID number, your car’s plate, the exact fee you paid and the address you lived at when you paid it, the call no longer sounds random.
Latvia’s national identity code cannot, by itself, open digital identity tools such as Smart-ID or Mobile-ID. The danger is more practical. A scammer who knows the code can begin a login attempt, cause an approval prompt to appear on a victim’s phone, and then ring while the prompt is on screen, pretending to be from CSDD or a bank and pushing the person to tap "approve" (NRA). Within days of the disclosure, fake CSDD-branded emails and SMS messages were already circulating (Delfi, tezinas.lv). The records go back to 2008, including people who have since left Latvia, so the fraud risk will not disappear with the news cycle (LSM).
Basic locks were missing
The break-in began over the weekend of 7–8 August. Latvia’s national cyber-response body, CERT.LV, was told only on Monday evening, 10 August (NRA). CSDD informed the public on 13 August that its website had been attacked. The full scale became public only on 18 August (eng.lsm.lv, LSM).
The failure was not some mysterious piece of cybercraft. Latvian reporting found that CSDD had not met several requirements for systems in the highest sensitivity category, the kind that hold enough personal data to affect most of the population. Multi-factor authentication, where a password must be backed by a second confirmation, was absent. So were penetration tests, the paid attempts to break into a system before real attackers do (BauskasDzīve/LETA, Delfi).
CERT.LV had offered between January and April to install network-monitoring sensors, effectively smoke alarms for suspicious traffic. They were being put in place only after the breach (LA.lv).
The politics moved quickly. President Edgars Rinkēvičs said CSDD’s leadership should not stay in post and asked prosecutors to examine the case. Both the CSDD board and council resigned (Delfi, Kauno diena). A separate IT failure had already forced the closure of Latvia’s Pāternieki border crossing with Belarus earlier this month, so the resilience of Latvian state IT was already a political issue before the CSDD breach made it harder to avoid.
A pattern, not an outlier
Latvia is not on its own here. Lithuania disclosed earlier this year that prosecutors believe more than 600,000 records were illegally copied from its national property and legal-entity registry, with unauthorised logins made through connected systems in other institutions (LRT). The route in was different, but the result was familiar: stolen administrative data, delayed clarity for the public, and warnings that criminals would pose as state agencies (LRT).
EU law already treats transport systems and public registries as critical infrastructure under NIS2, the bloc’s updated cybersecurity directive. It requires rapid incident reporting and gives regulators enforcement powers (ENISA, The Record). But when the institution at fault is a state body rather than a private company, accountability usually comes through audits, resignations and political pressure rather than fines.
The CSDD breach did not need a state-level operation. It needed an internet-facing system where basic protections were missing. Europe’s digital government depends on linked registries holding decades of administrative data, and governments keep asking citizens to trust those systems with more. That trust will depend less on new portals and smart services than on dull controls that actually work: passwords, access logs, second-factor checks and network alarms in place before attackers arrive.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 8/24/2026, 1:53:45 AM
- Pipeline run:
- eu_pipeline_20260824_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication