Ransomware Cripples Latvia’s Forestry Systems

The physical heart of the industry remains, while the digital pulse goes dark.
Cumadóireacht íomhá · tobriefOn 22 June, during Latvia’s Jāņi midsummer holiday, the screens went dark inside Latvijas valsts meži (LVM), the state forestry company. For anyone looking for a hunting permit, a forestry map or timber delivery data, the problem was immediate: about half of LVM’s IT systems had been knocked out by a cyberattack at a moment when fewer staff were likely to be watching them (LTV).
LVM took public services offline as a precaution, including digital maps, the Mednis hunting app and partner data exchanges. It began restoring systems from backups and refused to co-operate with the attacker. Latvia’s cyber-response team, CERT.LV, confirmed that stolen material had appeared online, though investigators were still working out what had actually been taken. Its assessment was that this was a commercially motivated ransom operation, not a state-linked campaign (LTV). In plainer terms, a criminal crew chasing money managed to disable services people use in ordinary daily life.
Old Wiring Behind New Walls
A large public body can look modern from the outside. There are web portals, mobile apps and interactive maps. Behind that, the wiring is often older: sign-in systems built before today’s security standards, contractor access that has not been audited in years, and software kept alive because the service cannot simply stop while everything is replaced.
That is where ransomware gangs tend to begin. They usually enter through a stolen password or an unpatched system, then work quietly to turn a low-level login into administrator control. By the time a ransom note appears, the attacker may have been inside for weeks (CISA). LTV reported that probing of LVM’s security systems had begun before the visible attack date (LTV).
Public organisations are exposed because they have little tolerance for downtime and long upgrade cycles. Old and new systems have to run together, sometimes for years (CISA, CrowdStrike). The danger sits in the join between the two.
The Pattern Next Door
Latvia’s case belongs to a wider Baltic problem. In Lithuania, authorities have been investigating the theft of more than 600,000 Real Estate Register extracts, including personal identification codes, from the state registry operator Registrų centras (LRT). The route in was stolen employee accounts, with the first illicit logins dating back to early 2026. The public learned of it only months later (TV3). About 1,000 people were preparing to sue the state (Verslo žinios).
The Latvian and Lithuanian cases are technically different, but they point to the same weakness: civilian digital systems now carry the weight of everyday public life, while their defences have not always caught up. Germany has already shown where this can end. In 2021, the district of Anhalt-Bitterfeld declared a disaster after ransomware hit, leaving citizen services disrupted for weeks (Landkreis Anhalt-Bitterfeld).
The New Rules Meet a Real Outage
NIS2, the EU’s cyber-resilience directive, is meant to drag this issue out of the IT department and into the boardroom. Operators of essential services must send an early warning within 24 hours of detecting an incident, provide a fuller notification within 72 hours, and deliver a final report within one month (EUR-Lex). Senior management is personally accountable for cybersecurity risk (European Commission).
Latvia transposed NIS2 into national law from September 2024, with minimum cybersecurity requirements due to enter force in July 2025 (Business.gov.lv). After the LVM attack, Latvia’s acting prime minister signed five resolutions requiring ministries to report on the security of state systems and on how incident information moves through government (Kulbergs). He tied the incident to overdue cybersecurity regulations, effectively admitting that rules on paper are only useful if the machinery behind them works.
The real test is practical. How long will LVM’s recovery take? Will citizens be told what personal data was exposed? Were the backups tested before they were needed? Can a minister say who, in their own chain of command, owns cyber risk for each public system? These questions are not Baltic questions alone. Every public operator in Europe faces them now, and NIS2 means they can no longer be left hanging.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 6/26/2026, 3:29:59 AM
- Pipeline run:
- eu_pipeline_20260626_015006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication