Latvia Cyberattack Exposes Personal Data of 1.2 Million People
Share
Latvia Cyberattack Exposes Personal Data of 1.2 Million People
- 1.2 Million Latvians Hit by Massive Government Data Breach
- Major Latvia Cyberattack Exposes IDs, Addresses and Vehicle Details
- Hackers Steal Personal Data of 1.2 Million People in Latvia
- Latvia Faces Huge Data Breach as Hackers Access 1.2 Million Records
- 1.2 Million People Affected by Major Cyberattack on Latvia’s Road Agency
A major cyberattack against Latvia’s Road Traffic Safety Directorate has exposed personal information linked to approximately 1.2 million people, affecting a huge portion of the country’s population and triggering investigations into how the breach occurred.
The Road Traffic Safety Directorate, known as CSDD, said attackers gained unauthorized access to historical payment receipt data covering records dating back to 2008. The compromised information includes sensitive details belonging to individuals as well as businesses and other legal entities.
Latvia has a population of roughly 1.8 million, meaning the breach potentially affects around two-thirds of the country.
What information was stolen?
According to CSDD and Latvia’s cybersecurity authorities, the stolen records contained several categories of personal and transaction information.
The exposed data includes:
- Names and surnames
- Personal identification numbers
- Company registration numbers
- Vehicle registration plate numbers
- Payment amounts
- Payment dates
- Addresses recorded when services were provided
- Company names
The agency said customer phone numbers and email addresses were not affected by the incident.
The breach involved historical payment receipts associated with services provided by CSDD, the government agency responsible for vehicle registration, driver’s licenses and other road safety services.
Hackers accessed records dating back to 2008
The attack took place between August 8 and August 10, 2026, according to Latvia’s Computer Emergency Response Team, CERT.LV.
Investigators determined that attackers were able to obtain historical payment receipt information stored in CSDD systems. The analysis identified data belonging to approximately 1.2 million individuals and 200,000 legal entities.
The incident is particularly serious because the stolen information can potentially be combined with data from other public sources to create detailed profiles of individuals.
Authorities warn of convincing scams
Latvian authorities are warning affected residents to be especially careful about unexpected emails, text messages and phone calls.
The stolen information could give criminals enough background information to make fraudulent messages appear legitimate. For example, a scammer who knows a person’s name, address and vehicle registration number could use those details to impersonate a government agency or another trusted organization.
Latvia’s cybersecurity authorities have advised residents not to open suspicious links and to verify information directly through official government websites or applications.
Officials have also warned users of Latvia’s digital identity services to be cautious about unexpected authentication requests. A leaked personal identification number does not by itself provide access to e-identity services, but it could be used as part of a social-engineering attack designed to trick victims into approving a fraudulent request.
CSDD faces questions over its response
The scale of the breach has also created a political and institutional crisis in Latvia.
CSDD did not immediately disclose the full extent of the stolen information. The attack occurred in early August, but the agency initially provided limited details before later confirming that data belonging to 1.2 million people and 200,000 legal entities had been accessed.
The agency’s board and supervisory council subsequently resigned following criticism over the handling of the incident and concerns about cybersecurity protections. Latvia’s president also called for scrutiny of the officials responsible for protecting the agency’s systems.
Criminal investigation underway
Latvian authorities have launched investigations to determine who carried out the attack and whether failures in cybersecurity controls contributed to the breach.
At this stage, no specific hacking group has been publicly confirmed as responsible.
The incident is now one of Latvia’s most significant data breaches, with the stolen information potentially creating risks for millions of people even though the attackers did not obtain customer email addresses or phone numbers.
For residents who may have been affected, cybersecurity officials recommend treating unexpected communications with caution, refusing authentication requests they did not initiate and checking important information directly through official channels.
The breach is another reminder that government databases containing routine information such as vehicle registrations and payment records can become highly valuable targets for cybercriminals — particularly when years of historical data are stored in a single system.




Leave a Reply