TechNewsReel
Live

Cyberattack on Latvia's CSDD Exposes Data of 1.2 Million People

A massive breach at the Road Traffic Safety Directorate has compromised personal records for two-thirds of the Latvian population.

TechNewsReel Newsroom · August 18, 2026

Latvia's Road Traffic Safety Directorate (CSDD) has fallen victim to a large-scale cyberattack that compromised the personal data of millions. The breach represents one of the most significant security failures in the country's administrative history, exposing a vast swath of the national population to potential fraud.

According to reports from MSN and other outlets, the attackers successfully stole the personal data of approximately 1.2 million individuals and 200,000 companies. The CSDD is the state-owned entity responsible for the critical tasks of vehicle registration, technical supervision of road vehicles, and the management of driver qualifications. Because the agency maintains comprehensive records on nearly every licensed driver and vehicle owner in the country, the volume of stolen data is exceptionally high.

Geopolitical Context

This attack occurs against a backdrop of heightened digital instability in the Baltic region. Latvia's geopolitical position and ongoing tensions with Russia have made the nation a frequent target for state-sponsored cyber activities. While the specific actors behind this breach have not been officially named in the confirmed reports, the targeting of essential state infrastructure is consistent with broader patterns of hybrid threats facing the region.

National Security Implications

The scale of the breach is staggering, impacting roughly two-thirds of Latvia's total population of approximately 1.8 million people. The theft of such comprehensive identity and vehicle data creates a fertile environment for identity theft and targeted financial fraud on a national scale.

Security officials have already observed the immediate fallout of the leak. There has been a documented increase in phishing attempts, with warnings issued regarding fraudulent communications that purport to be from the CSDD. These attempts typically leverage the stolen data to appear legitimate, tricking victims into revealing further sensitive information or transferring funds.

Next Steps

Authorities are now focused on mitigating the damage and warning the public to remain vigilant against suspicious emails and messages. While the theft of personal records is confirmed, the full extent of the compromised data—including whether specific financial identifiers were taken—remains a primary concern for investigators. Citizens are being urged to monitor their accounts for unauthorized activity as the government works to secure the CSDD's infrastructure.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.