Skip to main content
TECH_SCIENCE18 / 18 · story of the day3 min · 638 words · 17 sources

LVM hack leaks 7,000 passwords

Written by AIto brief AI · 4 ta’ Lulju 2026, 03:50
How it was written

The data remains exposed long after the digital locks are changed.

Image composition · tobrief
the text · 3 min read

On 22 June, Latvia's state-owned forestry company LVM switched off its entire IT infrastructure to stop an attacker from copying more files. Timber deliveries to most buyers resumed within four days, and most internal systems were back by 29 June. By then, however, around 44 GB of internal data had already been published online, and the amount stolen may be larger.

For a state forestry operator, four days is a quick recovery. Buyers still need timber, contractors still need instructions, and a public company cannot simply disappear while investigators work. LVM says it had functioning backups and received no ransom demand. Latvia's national cybersecurity authority CERT.LV confirmed the backups could be restored, contradicting early claims that they had been destroyed. The company kept operating. The real damage lies in what had already left the system.

One old server, two weeks of access

Modern ransomware is closer to a break-in than to a frozen laptop. The attacker finds a weak door, moves through the building, collects keys, copies documents, and then threatens publication unless money is paid. CISA's ransomware guide sets out the usual sequence: gain access, spread through the network, steal credentials, copy data, encrypt.

Cybersecurity expert Elvis Strazdiņš told Latvian media that the attacker allegedly spent nearly two weeks inside LVM's systems, entering through a server running outdated software. The intruder reportedly accessed around 7,000 employee passwords and installed malware. These are expert and media accounts, not official forensic conclusions. But the weakness they describe is familiar enough: one unpatched server can give an attacker a route into a much wider network.

Strazdiņš also said he contacted the hacker and was told the decryption price was about €618,600, set at 0.1% of LVM's revenue. LVM says no demand ever reached the company. CERT.LV chief Baiba Kaškina described the attacker as more interested in attention than money, saying the group had targeted organisations in several countries. There is no credible evidence of state sponsorship. The pattern looks like commercially driven ransomware with a publicity element attached.

Changed locks, photographed documents

LVM's backups protected its operations. They did not solve the harder problem: files that have already been copied cannot be pulled back. Passwords, security certificates, meaning the digital credentials that prove a server is genuine, and internal documents remain exposed even after the original systems are restored.

It is the digital equivalent of changing the locks after a burglary while knowing the intruder photographed the papers on the kitchen table. CERT.LV warned that compromised passwords, certificates, and digital keys all need to be replaced, and that leaked data creates continuing risks for third parties connected to LVM's systems.

When preparation becomes a legal question

That gap between "systems restored" and "data protected" is exactly where the EU's NIS2 Directive now sits. NIS2 covers 18 critical sectors and changes the legal test for operators: management must be able to show that risks were handled before an attack, not only that the organisation recovered afterwards. The directive makes leadership directly responsible for risk management and incident reporting.

For Malta, this is not a distant Latvian problem. The same logic applies to public-service operators, government systems, health services, financial services, and the digital infrastructure around iGaming and fintech. In a small state, one weak system can quickly become a national problem because suppliers, regulators, contractors, and public bodies often sit very close to each other.

Whether LVM falls fully within NIS2 depends on how Latvia classifies it. Full compliance timelines across member states stretch into 2027 and beyond, which means many operators are still building the controls they will soon have to prove they had.

LVM's case shows both sides of the test. The preparation that worked, including backups, staged restoration, and continuity planning, meant deliveries resumed within days. The preparation that failed, including keeping every server updated and detecting an intruder earlier, left thousands of credentials and gigabytes of files exposed. Kaškina put the imbalance plainly: defenders must secure everything, while an attacker needs only one weak point. That is now the standing challenge for every European public-service operator, whether it manages forests, hospitals, ports, or supply chains.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
7/4/2026, 3:40:33 AM
Pipeline run:
eu_pipeline_20260704_015011
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology