Latvia's CSDD Breach Exposes Data of 1.2 Million Citizens
The Road Traffic Safety Directorate's failure to report a massive data theft led to the resignation of its entire board and supervisory council.
A cyberattack on Latvia's Road Traffic Safety Directorate (CSDD) has exposed the personal information of approximately 1.2 million people. The breach represents a critical failure in national data protection, affecting a significant portion of the Latvian population.
According to reports from Cybernews, the stolen data includes highly sensitive identifiers such as personal ID numbers, full names, and home addresses. The breach also compromised vehicle-specific information, including license plate numbers and vehicle details, as well as historical payment records. The scale of the theft suggests a deep penetration of the CSDD's databases, leaving millions of records vulnerable to exploitation.
Regulatory Failures
The fallout from the attack was exacerbated by the agency's failure to follow mandatory security protocols. The CSDD did not notify the State Data Inspectorate or Cert.lv—Latvia's IT security incident response team—within the legally required 72-hour window. This delay in reporting hindered the immediate response to the breach and left affected citizens unaware of their exposure while the data was potentially being traded or utilized by malicious actors.
Political Consequences
The breach triggered a swift political crisis within the agency. Following public criticism from President Edgars Rinkēvičs, the entire board and supervisory council of the CSDD resigned. The mass departure of leadership underscores the severity of the negligence regarding both the initial security lapse and the subsequent failure to report the incident to national authorities.
Industry Implications
This incident highlights the acute vulnerability of the Baltic region to cyber activity. For the industry, the CSDD breach serves as a warning that the failure to implement rapid notification systems can turn a technical security failure into a total institutional collapse. On a national level, the exposure of personal ID numbers and payment history significantly increases the risk of identity theft, targeted phishing campaigns, and financial fraud for millions of Latvians.
Next Steps
Attention now turns to how the Latvian government will restructure the CSDD's leadership and what systemic changes will be implemented to prevent similar lapses in the future. While the scale of the breach is confirmed, the full extent of how the stolen data is being used in the wild remains a primary concern for security analysts and the State Data Inspectorate.