Hackers Steal Identity and Vehicle Registration Data from Latvia’s Road Traffic Safety Authority

Views: 64 views

479/69 Wednesday, September 2, 2026

Latvia’s Road Traffic Safety Directorate (CSDD) disclosed a data breach after attackers gained access to the agency’s systems and stole data belonging to approximately 1.2 million individuals and around 200,000 legal entities. The number of affected individuals represents roughly two-thirds of Latvia’s population. CERT.LV stated that the attackers obtained the data between August 8 and August 10, 2026, while CSDD first became aware of the incident on August 13. The agency later published details of the affected data types on August 18 and added a feature to its e-services portal, e.csdd.lv, on August 27, allowing users to log in and check whether their data was stolen and what types of information were affected.

The stolen data came from payment receipts dating back to 2008 and included names, national identification numbers or legal entity registration numbers, payment amounts and dates, vehicle registration numbers, and addresses recorded at the time of service. However, CSDD stated that customer usernames, passwords, phone numbers, and email addresses were not affected. CERT.LV’s investigation found that the attackers exploited a vulnerability in a CSDD system exposed to the internet and that some necessary cybersecurity requirements had not been fully implemented. According to De Facto, the initial access may have occurred during the night of August 7 into August 8 through CSDD’s medical platform, which is used by approximately 200 doctors to submit medical certificates for drivers.

The incident has led to regulatory and security consequences. Reports indicate that CSDD did not notify Latvia’s State Data Inspectorate within the required 72-hour timeframe, resulting in the resignation of the supervisory board. The agency’s management board later also resigned following a request from Latvia’s Minister of Transport. Although passwords were not stolen, the leaked information could be used to make email, SMS, or phone scams appear more convincing, particularly scams impersonating CSDD or other authorities. In addition, Latvia’s State Police, armed forces, and agencies involved in operational missions are assessing whether some vehicle registration numbers need to be changed, as the leaked data could identify vehicles used in sensitive operations. CSDD advises citizens to check their information directly through e.csdd.lv, while CERT.LV warns users not to approve Smart-ID or eParaksts authentication requests that they did not initiate themselves.

Source: https://hackread.com/hackers-steal-identity-vehicle-data-latvia-csdd/