GoFirm
Back to Blog
Case Studies·4 min read

The breach that exposed 1.2 million Latvians' payment records also emptied the agency's leadership

By GoFirm

Overnight between 7 and 8 August 2026, an unidentified attacker gained access to a system belonging to the Road Traffic Safety Directorate (CSDD), the Latvian state agency responsible for vehicle registration, driver's licensing and road safety services under the country's Transport Ministry. Latvia's national cyber incident response team, later confirmed that the intruder had exploited a vulnerability in a CSDD system exposed directly to the internet, and that the agency had failed to meet several mandatory cybersecurity requirements. CSDD's own employees, not the vendor paid to watch for exactly this, caught the intrusion and shut it down within hours.

Once inside, the attacker pulled historical payment receipt data stretching back to 2008: personal identification numbers, company registration numbers, vehicle licence plate numbers, payment amounts and dates, and the addresses attached to vehicle registration certificates. By the time CSDD completed its analysis on 25 August, the confirmed toll stood at more than 1.2 million individuals and 200,000 businesses and other legal entities, in a country of just 1.8 million people. Usernames, passwords, phone numbers and email addresses were reportedly not affected, but https://www.google.com/url?q=http://CERT.LV&source=gmail&ust=1787814968162000&sa=E warned that the stolen identification and payment data was precisely the material needed to run convincing follow-on social engineering and fraud campaigns against the same population.

CSDD had contracted Latvian telecoms and technology company Tet to maintain its IT infrastructure and monitor for intrusions under a five-year agreement covering firewall and incident monitoring. Tet did not detect the breach and did not alert CSDD. CSDD then took days to notify and, according to Latvian broadcaster LSM, missed the 72-hour window in which it was legally required to notify the State Data Inspectorate, a delay regulators are now investigating alongside the breach itself.

The political cost arrived faster than any technical fix. Latvian President Edgars Rinkevics called the breach a threat to national security and said CSDD's leadership could not continue in its role. A member of parliament made the same demand publicly. Within days, CSDD's supervisory board had resigned, and the agency's director, former Riga mayor Aivars Aksenoks, said he intended to step down once the investigation was complete. It was the second major breach of a Latvian state-owned organisation in three months, after state forestry company LVM was hit by ransomware in June. State police have opened criminal proceedings, and CSDD reported fending off a second attempted attack the following weekend after emergency security improvements were made.

The defences that failed here were not absent. CSDD had a contracted security vendor, a five-year monitoring agreement covering its firewall and infrastructure, and mandatory cybersecurity requirements it was supposed to meet. What it did not have was a control that treated the bulk export of eighteen years of citizen payment data as the high-impact event it actually was. A vulnerability got the attacker through the perimeter. Nothing inside stopped the extraction that followed, and the vendor paid to watch for exactly that never raised the alarm.

A perimeter vulnerability is not an execution event. Pulling a database covering 1.2 million citizens' identification numbers and eighteen years of payment history out of a government system is. GoFirm treats that extraction as the moment that matters, regardless of how the attacker got inside. Before a bulk export at that scale can run, a confirmation request goes to the named data controller or CSDD's designated authority on their registered device, requiring a biometric confirmation over a channel entirely separate from the system being accessed.

An attacker holding a freshly exploited vulnerability or a stolen session has no way to produce that confirmation. They can be inside the network and still be unable to move the data out, because the export itself, not just the intrusion, is the action that requires authorisation. A vulnerability, however well hidden, cannot generate a fingerprint or a face on a device it does not control. The execution boundary holds regardless of how the attacker got past the perimeter.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.

References

1. Antoniuk, D. 2026. Latvian officials resign after cyberattack exposes data on 1.2 million people. The Record from Recorded Future News, 19 August 2026.
2. LSM (Latvian Public Broadcasting). 2026. Latvian CSDD was late to report cyber attack. LSM.lv, 24 August 2026.
3. BNN News. 2026. Data of 1.2 million people leaked in CSDD cyberattack in Latvia, including personal ID numbers and addresses. Baltic News Network, 2026.

Share this article