Latvia’s Road Traffic Safety Directorate confirmed on August 18 that a cyberattack exposed personal data relating to 1.2 million people, with the stolen information contained in payment receipts dating back 18 years.
The agency disclosed that attackers obtained personal identification numbers or company registration numbers, full names, payment amounts, transaction dates, vehicle registration numbers, and addresses registered at the time services were received. The breach was first detected on August 13 when the CSDD’s public-facing website suffered disruptions, and the full scope of the data theft was revealed five days later after a forensic investigation.
Follow-Up Attack Blocked Over the Weekend
Māris Puriņš, head of the CSDD’s IT department, said the agency also faced a targeted follow-up attack over the weekend, but security improvements implemented after the initial intrusion blocked it. He stressed that contact details including telephone numbers and email addresses were not compromised, and that address information obtained by the attackers is incomplete in some cases.
The CSDD has restricted the ability of unauthorized users to process vehicle information based on national registration numbers, limiting what attackers can extract about vehicle make and model. The agency said it has informed the State Data Inspectorate and is cooperating with law enforcement to identify the perpetrators.
Fraud Risk From Leaked Identification Numbers
Varis Teivāns, deputy head of Cert.lv, Latvia’s national cybersecurity response team, warned that the most significant danger is that the data will power social engineering campaigns. He said that when fraudsters have a person’s name, identification number, car registration, address or payment details, they can craft highly credible personalized phishing messages.
The public has been urged to avoid clicking links in unsolicited messages and to verify any CSDD-related communications through the official e.csdd.lv website or the CSDD mobile app. Cert.lv specifically cautioned against trusting messages that include accurate personal details, which the leaked data now makes easy to fabricate.
The CSDD breach adds to a wave of cyber incidents hitting Latvian institutions in recent days. Latvian State Forests reported a separate cyberattack on August 17, attributing it to miscommunication among staff. The cluster of incidents has raised questions about the cybersecurity readiness of Latvia’s government-linked agencies, even as the country simultaneously manages border security pressures along its eastern frontier.
CSDD’s day-to-day service provision has not been disrupted. The agency continues to offer all services in person and through its e-CSDD digital platform while the investigation continues.
Sources: LSM English (Latvian Public Media); Cert.lv advisory; CSDD official statement, all August 18 2026.
discussion