Latvia Breach Hands Scammers Fresh Data

Decades of ordinary transactions become a permanent catalogue for fraud.
Image composition · tobriefAnyone who registered a car in Latvia since 2008 now has reason to worry. Attackers broke into the country’s road-traffic authority, CSDD, and copied payment-receipt records linked to about 1.2 million people and roughly 150,000–200,000 companies (LSM, BNN). In a country of fewer than two million inhabitants, that means most adults are affected. No bank account was emptied. What criminals obtained is something more durable: the material needed to make fraud sound personal, official and believable.
For Maltese readers, the lesson is not distant. Malta also runs on compact state databases where one authority’s records can cover a large share of the adult population. When a small country digitises public services, a breach is rarely narrow. It becomes a national problem very quickly.
What a scammer now knows
The stolen data reads like a ready-made file on the person. It includes names, national identity codes, vehicle registration plates, payment amounts, payment dates, and the home address recorded when the service was used (tezinas.lv, inbox.lv). Phone numbers, email addresses, bank details and login credentials were not taken (NRA). That sounds comforting only until the scam call starts. A caller who knows your ID number, your car’s plate, the exact fee you paid and the address you had at the time already sounds like someone from the state.
The identity code alone cannot open Latvia’s digital identity systems, including Smart-ID and Mobile-ID. The danger is social engineering. A scammer can start a login attempt using the code, make an approval request appear on the victim’s phone, then call pretending to be CSDD or a bank while the person is looking at the prompt and pressure them to tap "approve" (NRA). Fake CSDD-branded emails and SMS were already circulating within days of the disclosure (Delfi, tezinas.lv).
The fraud risk will not disappear after a few weeks. The records go back nearly two decades and include people who registered a car in 2008 and have since left Latvia (LSM). Old data is still useful when it helps a criminal sound legitimate.
Basic locks were missing
The intrusion began over the weekend of 7–8 August. Latvia’s national cyber-response body, CERT.LV, was told only on Monday evening, 10 August (NRA). CSDD announced on 13 August that its website had been attacked. The public learned the full scale only on 18 August (eng.lsm.lv, LSM).
The failure was not especially complex. Latvian reporting found that CSDD had not met several requirements for systems classified at the highest sensitivity level, the category used when the data held is broad enough to affect most of the population. Multi-factor authentication, meaning a second check beyond a password, was missing. So were penetration tests, where paid specialists try to break into a system before real attackers do (BauskasDzīve/LETA, Delfi).
CERT.LV had offered between January and April to install network-monitoring sensors, the equivalent of smoke alarms for suspicious traffic. They were being installed only after the breach (LA.lv).
The political response came quickly. President Edgars Rinkēvičs said CSDD’s leadership should not remain in office and asked prosecutors to examine the case. Both the CSDD board and council resigned (Delfi, Kauno diena). The timing made the damage worse politically. A separate IT failure had already forced Latvia to close the Pāternieki border crossing with Belarus earlier this month, so the resilience of state IT systems was already under scrutiny.
A pattern, not an outlier
Latvia is not an exception. Lithuania disclosed earlier this year that prosecutors believe more than 600,000 records were illegally copied from its national property and legal-entity registry, after unauthorised logins through connected systems belonging to other institutions (LRT). The route was different, but the result was familiar: administrative data stolen, public clarity delayed, and warnings that criminals would impersonate state agencies (LRT).
EU law already treats transport systems and public registries as critical infrastructure under NIS2, the bloc’s updated cybersecurity directive. It requires fast incident reporting and gives regulators enforcement powers (ENISA, The Record). The weak point is enforcement against the state itself. When the failed body is a public agency rather than a private company, accountability usually comes through audits, resignations and political pressure, not a simple fine.
That should matter in Malta. A micro-state does not have the luxury of treating public-sector cybersecurity as a back-office issue. Identity, transport, tax, health and business records sit close together because the state itself is small. The risk is not only that a system goes down. It is that a breach gives criminals enough official detail to sound like Castille, Transport Malta, a bank or a kunsill lokali.
The CSDD breach did not need a state-level cyber operation. It needed an internet-facing system where basic controls were missing. Europe’s digital government is built on connected registries holding decades of administrative data, while governments keep asking citizens to trust those systems with more. That trust now depends less on launching new digital services than on making the unglamorous controls work: strong authentication, access logs, testing, monitoring sensors, and a response plan that starts before the damage becomes public.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 8/24/2026, 1:53:45 AM
- Pipeline run:
- eu_pipeline_20260824_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication