A Breach Reached 1.2 Million Latvians. The Records Went Back to 2008.
A cyberattack on Latvia’s Road Traffic Safety Directorate, CSDD, exposed historical payment-receipt data linked to 1.2 million people and 200,000 legal entities. The records went back to 2008.
The breach is significant not because passwords were stolen, but because the compromised archive combines identity, location, vehicle, and transaction context at national scale. That combination can make a fraudulent message or authentication prompt look uncomfortably credible.
The attackers reached an 18-year archive
According to the joint CSDD and CERT.LV disclosure, the attacker obtained data between 8 and 10 August 2026 from payment receipts covering services supplied since 2008. The affected fields can include:
- a Latvian personal identity number or company registration number;
- a person’s name or company name;
- the payment amount and date;
- a vehicle registration plate;
- the address recorded when the service was provided.
CSDD says customer telephone numbers, email addresses, usernames, and passwords were not affected. It also says address information was not complete in every record. Those limits matter, but they do not neutralise the fraud value of the dataset.
An identity number is not a password, but it can start the fraud
CERT.LV’s warning is precise. A personal identity number alone does not grant access to Smart-ID, eParaksts mobile, e-CSDD, health, tax, or government services. It can, however, be used as an account identifier in some authentication flows. An attacker who knows the victim’s name, vehicle, old address, and payment history can use those details to make a malicious login request or support call appear legitimate.
The highest-probability downstream harm is therefore targeted social engineering. A message can refer to a real registration plate, a recognisable CSDD transaction, or a former address, then ask the recipient to approve an authentication request or follow a payment link. Knowledge is being used as borrowed trust.
CERT.LV advises people never to approve a Smart-ID or eParaksts mobile authentication request they did not initiate. It also recommends opening official services manually rather than using links in messages that claim to come from CSDD or another institution.
The breach path was an internet-facing CSDD application
Later Latvian public-service reporting said the attack used a vulnerability in an internet-accessible CSDD system. Tet’s internal investigation placed the entry point in an application managed by CSDD, rather than the network and infrastructure covered by Tet’s contract.
Latvian reporting also said several mandatory information-system security requirements had not been met and that incident notification was delayed. The entire CSDD board and supervisory council resigned. The State Police opened a criminal case, and Latvia’s Prosecutor General and Data State Inspectorate began reviews.
The retention decision shaped the blast radius
The attackers did not need to compromise every modern customer account to create population-scale harm. They reached a long-lived archive whose individual records had accumulated far beyond the immediate purpose of a single payment.
That makes the incident a data-retention story as much as an application-security story. Organisations should not ask only whether a database is encrypted or whether an application is patched. They should also ask why an internet-facing service can reach 18 years of identity-linked transaction history, whether that access can be segmented, and which fields still need to exist in production systems.
What defenders and affected people should do
- Treat vehicle, address, and payment details quoted by a caller or message as compromised context, not proof of identity.
- Reject authentication prompts that you did not initiate, even when the request contains accurate personal information.
- Open e-CSDD and other government services directly through their official site or application.
- For public-sector operators, segment historical archives from internet-facing services and minimise the fields retained online.
- Test application-layer exposure separately from network infrastructure. Contract boundaries do not remove security ownership.
- Exercise incident notification and public communication so the fraud-warning window begins as soon as credible evidence exists.
The official CSDD and CERT.LV notice was first published on 13 August and updated on 18 August with the confirmed scope. The source supplied dates but no publication times. The incident did not disrupt CSDD’s in-person or online services, but its long-term impact will be measured in fraud attempts, institutional trust, and the cost of rebuilding a national security baseline.
Continue the series: European National Cyber & Digital Law Series index


