Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 20, 2026 · 6 min read

Latvia Officials Resign After Breach Hits 1.2M

Latvia has about 1.85 million residents. On 18 August 2026 the country's Road Traffic Safety Directorate confirmed that attackers had taken personal data on 1.2 million of them, plus records on roughly 200,000 companies. The next day the agency's entire management board and supervisory council were gone.

Two thirds of a country in one file. Scaled to the United States, that is a breach of roughly 220 million people, taken from the agency that registers cars.

Key Takeaways

  • CSDD, Latvia's Road Traffic Safety Directorate, confirmed on 18 August 2026 that attackers stole personal data on 1.2 million people and about 200,000 legal entities.
  • The intrusion happened overnight between 7 and 8 August 2026 through an unpatched, internet facing system, and reached CERT.LV only on 10 August.
  • The stolen records span 18 years of payment receipts back to 2008: personal identification numbers, names, addresses, licence plates and payment amounts. Passwords and bank details were not taken.
  • CSDD's management board and supervisory council both resigned on 19 August 2026, and President Edgars Rinkēvičs referred the conduct of CSDD officials to the prosecutor general.
  • CERT.LV deputy head Varis Teivāns noted that Class A state systems in Latvia must undergo penetration testing and use multi factor authentication, requirements CSDD had not met.

What Happened to Latvia's Vehicle Registry?

Attackers broke into an internet facing CSDD system overnight between 7 and 8 August 2026, exploiting a vulnerability that had never been patched and, by the agency's own account, never been detected. CSDD's own specialists spotted it and cut it off within hours. Reaching CERT.LV, Latvia's national computer emergency response institution, took two more days. The public heard nothing until 13 August; the scale stayed unquantified until 18 August.

CERT.LV's read is not the language you use for a lucky scan: targeted, requiring advance preparation, showing significant technical competence. Prime Minister Andris Kulbergs, in office since 28 May 2026, said a hybrid operation by another state could not be ruled out. Nobody has been named. A second attempt the following weekend was blocked. The Record also reports that the agency had failed to meet mandatory national cybersecurity requirements.

What Data Was Actually Stolen?

Eighteen years of payment receipts, running from 2008 to the present. For individuals that means the personal identification number, Latvia's personas kods, plus name, the address recorded on the day of service, plate numbers, and payment amounts and dates. For the 200,000 legal entities it means company registration numbers and the same transaction history, as Latvian public broadcaster LSM reported.

No passwords, no usernames, no phone numbers, no email addresses, no bank details. What they took instead cannot be changed. A password rotates in a minute; a personas kods does not rotate at all. Latvia issues one per person, it threads through banking, healthcare and government services, and it never expires. Attach it to a home address and a licence plate and you have a dossier that stays accurate for years, the same problem behind the Texas hunting licence breach that exposed 3 million driver's licences.

Empty service counters in a northern European vehicle registration office at the end of the day, blank metal licence plate blanks stacked on a steel cabinet in the foreground

Why Did the Entire Board Resign in 11 Days?

Because Latvia's political machinery moved faster than its forensic investigation. On 19 August 2026, eleven days after the intrusion and one day after the numbers went public, both the management board and the supervisory council stepped down. Chief executive Aivars Aksenoks, a former mayor of Riga, said he would leave once he had helped finish the investigation. Transport Minister Rihards Kozlovskis ordered an expedited review of both boards' responsibility, due in early September, covering the cybersecurity contract too.

President Rinkēvičs called the episode scandalous and referred CSDD officials to the prosecutor general. Set that against the usual pattern. The UK's ACRO Criminal Records Office was breached three times without noticing, and the French tax authority breach that hit 678,000 taxpayers produced no board level departures. European public sector breaches almost never cost anyone a job. Latvia is the outlier, and a small country can afford that clarity when two thirds of the electorate is in the file.

Who Was Supposed to Be Watching?

A paid contractor was, and it saw nothing. CSDD retains SIA Tet for infrastructure maintenance, firewall protection, monitoring and incident detection under a five year contract now in its final year. Aksenoks said his own specialists found and stopped the intrusion, that Tet knew nothing when contacted afterwards, and that CSDD pays the company a substantial monthly sum for exactly that monitoring.

Most coverage has treated the resignations as the story. The contractor gap is the transferable one. Tet is 51 percent owned by state asset manager Possessor and 49 percent by Tilts Communications, a Telia subsidiary, so the state was in effect paying itself to watch itself. CERT.LV's monitoring sensor arrangement with CSDD had never been formalised either: it lived as an email between two employees, sent for signature only after the breach, according to reporting on the accountability process.

What This Means for Your Inbox

CERT.LV and CSDD have both warned that the likeliest use of this data is social engineering, and email is where most of it lands. A generic phishing message is easy to dismiss. A message that greets you by name, quotes your correct personal identification number, cites your licence plate and references a payment you really made to CSDD in a year you really made it is a different object, and the standard advice about spotting typos does nothing against it.

Latvian residents should treat anything claiming to come from CSDD as unverified, and reach the agency by typing e.csdd.lv rather than following a link. The same reflex belongs on messages from banks, insurers or the tax service, because the stolen identifiers open all of those conversations. Journalists and activists whose home address is sensitive should assume it now circulates alongside a plate number, which is a physical safety question, not an inbox one.

AI now writes the majority of phishing emails reaching inboxes, so personalisation that once took manual research is now a template variable. This leak used to be material criminals needed months to work through. Now it takes an afternoon.

What Compliance Teams Should Take From This

Processor liability in Latvia is settled precedent. In October 2025 the Data State Inspectorate fined SIA ZZ Dats 300,000 euros under Article 32 of the GDPR over a breach affecting data held for dozens of municipalities, and the municipalities were themselves reprimanded for inadequate oversight of their processor. The template is unambiguous: the contractor pays, and the controller is still faulted for not supervising it.

  • Contracted monitoring is not evidence of monitoring. Ask your vendor to name the last thing they found that your own team had not.
  • Payment archives are breach surface. Eighteen years of receipts served no live operational purpose. Retention schedules are a security control.

Latvia's National Cyber Security Law, transposing the EU NIS2 Directive, came into force on 1 September 2024 and carries management accountability provisions most member states adopted on paper and never tested. This is the first prominent case of a board leaving over them. With GDPR fines already past 7.1 billion euros in 2026, the Kozlovskis review and the prosecutor general's examination are the documents to watch. If either finds individual liability, the calculus changes for every board over a Class A system in the EU.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.