Skip to main content
TECH_SCIENCE14 / 18 · story of the day3 min · 722 words · 25 sources

Ransomware Hits Latvia’s Forestry Systems

Written by AIto brief AI · 26 ta’ Ġunju 2026, 03:50
How it was written

The physical heart of the industry remains, while the digital pulse goes dark.

Image composition · tobrief
the text · 3 min read

On 22 June, Latvia’s state forestry company, Latvijas valsts meži (LVM), was hit by a cyberattack that knocked out about half of its IT systems during the Jāņi midsummer holiday, when staffing was lighter than usual (LTV). The services affected were ordinary but essential: hunting permits, forestry maps, the Mednis hunting app, and timber delivery data.

LVM took public services offline as a precaution, including digital maps, the Mednis app, and partner data exchanges. It began restoring systems from backups and said it would not cooperate with the attacker. Latvia’s cyber-response team, CERT.LV, confirmed that stolen material had appeared online, though investigators were still checking what data had actually been taken. Its assessment was that this was a commercially motivated ransom attack, rather than a state-linked operation (LTV).

For Maltese readers, the point is familiar enough. When a public digital system goes down, it is not an abstract IT problem. It is the permit, the form, the map, the registry entry, the thing people need to get on with their work.

Old Wiring Behind New Walls

A large public organisation often looks modern from the outside: web portals, mobile apps, interactive maps. Behind that front end, older systems may still be doing much of the work. Sign-in tools can predate current security standards. Contractors may have remote access that has not been properly reviewed for years. The public does not see these weak points, but attackers look for them first.

Ransomware groups usually enter through a stolen password or an unpatched system. They then try to turn a low-level login into administrator control, moving through the network until they can lock or steal what matters. By the time a ransom note appears, the attacker may have been inside for weeks (CISA). LTV reported that probing of LVM’s security systems began before the visible attack date (LTV).

Public bodies are exposed because they cannot easily go offline, and because old and new technology often have to run together for years while upgrades are planned and funded (CISA, CrowdStrike). The risk sits in the gap between legacy systems and newer digital services.

The Pattern Next Door

Latvia’s case fits a wider regional pattern. In Lithuania, authorities have been investigating the theft of more than 600,000 Real Estate Register extracts, including personal identification codes, from the state registry operator Registrų centras (LRT). The access route ran through stolen employee accounts, with the first illicit logins dating back to early 2026. The public found out only months later (TV3). Around 1,000 people were preparing to sue the state (Verslo žinios).

The two incidents differ technically, but they point to the same weakness: civilian digital systems that carry everyday public life have not been defended with the seriousness their role now requires. Germany has already shown where this can lead. In 2021, the district of Anhalt-Bitterfeld declared a disaster after a ransomware attack disrupted citizen services for weeks (Landkreis Anhalt-Bitterfeld).

The New Rules Meet a Real Outage

NIS2 is the EU directive that turns cybersecurity from a technical concern into a board-level responsibility. Operators of essential services must send an early warning within 24 hours of detecting an incident, submit a detailed notification within 72 hours, and deliver a final report within one month (EUR-Lex). Senior management is personally accountable for cybersecurity risk (European Commission).

Latvia transposed NIS2 into national law from September 2024, with minimum cybersecurity requirements due to enter into force in July 2025 (Business.gov.lv). After the LVM attack, Latvia’s acting prime minister signed five resolutions requiring ministries to report on the security of state systems and on how incident information moves through government (Kulbergs). He linked the incident to overdue cybersecurity regulations, effectively acknowledging that rules on paper only matter if the machinery behind them works.

The practical test now goes beyond Latvia. How long will LVM need to recover? Will citizens be told what personal data was exposed? Were backups tested before the attack? Can a minister say who, in the chain of command, owns cyber risk for each public system?

Those questions apply across Europe, including Malta. NIS2 gives governments less room to treat cyber resilience as a back-office matter. When public systems carry daily life, their failure becomes a public-service failure.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
6/26/2026, 3:29:59 AM
Pipeline run:
eu_pipeline_20260626_015006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology