Latvia’s CSDD data breach exposed payment-record information linked to about 1.2 million people and roughly 200,000 legal entities, turning a compromise at the state road-traffic agency into a government accountability crisis. The CSDD supervisory board resigned, while reporting on August 19 said the management board also decided to step down after pressure from President Edgars Rinkēvičs and Transport Minister Rihards Kozlovskis.
CSDD handles vehicle registration, driving licences, technical inspections and related services. The Transport Ministry holds its state capital shares. The agency said attackers obtained data from payment receipts dating to 2008, records spanning about 18 years.
What data was exposed in the Latvia CSDD data breach?
According to CSDD, the stolen records included people’s names, personal identification numbers or company registration numbers, vehicle registration numbers, payment amounts and dates, and addresses recorded for vehicle-registration purposes. The agency said address data was incomplete in some cases.
CSDD said customer phone numbers, email addresses, usernames and passwords were not compromised. That distinction is useful, though it does not make the remaining data harmless. CERT.LV, Latvia’s national cyber incident-response body, warned that the mix of identity, vehicle and payment details could support personalised social-engineering and fraud attempts.
In practice, that could mean a message or call that cites a real vehicle plate, an old payment or an address to impersonate CSDD more convincingly. CERT.LV’s warning concerns possible follow-on scams, not confirmed fraud. For the mechanics behind those tactics, see Kernel’s guide to recognizing social-engineering threats.
Who resigned and what is still under investigation?
The CSDD supervisory board submitted its resignation to Kozlovskis before a meeting on August 19, Baltic News Network reported. Xinhua reported that both the supervisory council and management board decided to step down that day. BNN separately reported that Kozlovskis told management-board members he saw no basis for them to remain and called for their resignations.
CSDD management-board chair Aivars Aksenoks said he was prepared to leave after helping deal with the incident and its consequences. Rinkēvičs had said the breach threatened national security and called for CSDD leadership to go, according to Latvian Public Media.
Kozlovskis ordered an expedited internal investigation into the attack, the breach and responsibility. It will also examine CSDD’s cybersecurity-services contract with Latvian technology company Tet. Rinkēvičs separately asked the prosecutor general to review officials’ handling of data protection. Cybersecurity and data-protection authorities are investigating, and state police have opened criminal proceedings.
Attribution remains unresolved. CERT.LV said preliminary findings indicated a targeted attack that had been prepared in advance and used technically capable methods. CSDD chief Aksenoks said Tet, which provides parts of CSDD’s infrastructure and monitoring, had not detected the intrusion; Tet said responsibility could not be fixed until investigators established how access was gained and where controls failed.
CSDD said ordinary online and in-person services continued through the incident. It also limited a feature that let users retrieve a vehicle’s make and model from a registration number, and said it blocked a later attempted attack after making security changes.
This story draws on original reporting from The Record.