Summary
- Attackers extracted historic payment-receipt data covering 1.2 million people and 200,000 legal entities from Latvia’s CSDD.
- Exposed records include personal or company identifiers, names, vehicle registrations, addresses, payment amounts, and dates.
- The incident has triggered management consequences and scrutiny of how public bodies govern internet-facing systems, retained data, and outsourced security services.
A cyberattack on Latvia’s Road Traffic Safety Directorate has become a public-sector governance problem after attackers extracted historic payment records concerning 1.2 million people and 200,000 legal entities, an unusually large exposure in a country with a population of roughly 1.8 million. The Ceļu satiksmes drošības direkcija, known as CSDD, says the breach took place between 8 and 10 August and affected receipt data retained from services dating back to 2008.
The compromised information includes personal identification or company registration numbers, names, payment amounts and dates, vehicle registration numbers, and addresses recorded when a service was provided. CSDD says customer usernames, passwords, telephone numbers, and email addresses were not part of the extracted dataset, while its public-facing services remained available during the incident response.
That combination makes the breach principally a confidentiality failure rather than a prolonged service outage, but continued availability does little to reduce the value of the information already removed. Historic records combining a person’s identity, vehicle, address, and transactions can provide criminals with enough context for convincing impersonation or phishing even without a password.
CERT.LV has warned about follow-on fraud and says technical information identified during its investigation has been passed to CSDD and law-enforcement authorities. The cyber incident has also prompted a wider examination of management responsibility, moving the response beyond the immediate work of closing the vulnerability.
Long-lived databases accumulate risk
The age of the records demonstrates the security cost created by retention. Organisations may keep payment information for legal, accounting, operational, or audit purposes, yet data that remains useful internally continues to carry exposure long after the original transaction has finished.
Public bodies often accumulate this problem gradually because older systems remain connected to newer digital services while legal requirements make deletion more complicated than simply deciding that historical information has little commercial value. As databases grow, the consequences of a single access-control or application failure can increase without any visible change in the service experienced by the public.
The CSDD incident therefore raises questions not only about how the attackers entered but also about why an exposed system could reach such a large historic dataset. Segmentation and least-privilege access can reduce the damage created by a compromised application by ensuring that an internet-facing service cannot automatically retrieve every record held elsewhere in the organisation.
Those controls depend on a clear understanding of system architecture, which can be difficult across public-sector estates built over many years. Databases, applications, contractors, interfaces, and identity platforms may have been introduced at different times under different procurement programmes, leaving security teams to manage dependencies that were never designed as one coherent system.
Outsourcing does not transfer accountability
The incident has also placed attention on the relationship between CSDD and technology suppliers providing monitoring and cyber-security services. Managed security can give a public body access to expertise and tools it could struggle to maintain internally, but a contract cannot remove the organisation’s responsibility for understanding what is monitored and how alerts are handled.
Effective arrangements have to specify which logs and systems are covered, what activity should trigger escalation, who receives the alert, how quickly action must be taken, and which party has authority to isolate an affected service. Without those operational details, both supplier and customer can believe the other is watching the critical part of the environment.
Management accountability has consequently become part of the response, including leadership changes at CSDD and government demands for a clearer assessment of responsibility. That is consistent with a wider shift in European cyber policy, where incidents affecting essential or public services are increasingly treated as governance failures rather than technical events that can be delegated entirely to an IT department.
The Data State Inspectorate is separately examining whether appropriate technical and organisational measures were in place to protect personal information, adding a data-protection dimension to the cyber investigation. The outcome will depend partly on what controls were reasonable given the sensitivity, age, and scale of information retained.
CSDD’s services continued operating, which might once have been considered evidence that the organisation remained resilient. The breach shows the limitation of that definition because a digital public service can remain online while still losing enough personal data to create significant harm and political consequences.
Latvia now has the immediate task of securing CSDD’s systems and the broader one of deciding what the incident reveals about other public bodies with similarly long-lived databases, internet-facing applications, and outsourced technology. The most useful outcome would be a review extending beyond the single weakness exploited in August, because the combination of historic records and interconnected services is unlikely to be unique to one agency.












