Massive Cyberattack in Latvia Exposes Data of 1.2 Million Drivers

A significant cyberattack in Latvia has revealed the personal data of approximately 1.2 million drivers, prompting concerns about potential identity theft and fraud. The breach, which affects an archive of payment data spanning the last 18 years, includes names, personal identification codes, vehicle registration numbers, and addresses. However, hackers did not gain direct access to bank accounts.
While immediate financial loss is not a threat, the stolen data poses risks of phishing and unauthorized access to services such as Smart-ID and eParaksts, as warned by authorities. The root cause of the breach was an unaddressed vulnerability in the system of the Road Traffic Safety Directorate (CSDD), which failed to implement basic security measures for Class A infrastructure. Notably, the agency neglected to establish two-factor authentication and penetration testing, and it previously declined to install specialized protective equipment from Cert.lv.
Latvian Prime Minister Andris Kulbergs criticized CSDD leadership for their delay in notifying security services and expressed concerns that another state may be behind the attack. In response, the State Police has initiated a criminal investigation, and a service review is underway regarding CSDD management, although Chairman Aivars Aksenoks has refused to resign.
Drivers are strongly advised to exercise caution by avoiding links from suspicious messages claiming to be from CSDD and not to confirm any Smart-ID or eParaksts requests unless initiated by themselves.




