Tuesday, 18 August 2026
Rīga TV

World and Latvian news in one place

LatviaPublished: 18 August 2026 at 19:00

Expert: Data stolen from Latvia's road authority CSDD could be exploited for years

Cybersecurity expert Elviss Strazdiņš warns that data stolen in the recent cyberattack on Latvia's road traffic safety directorate (CSDD) could end up with Russian scammers and remain usable for fraud for years to come. He stresses that where the data ends up matters more than who carried out the attack.

Foto: Jauns.lv

Following a recent cyberattack on Latvia's Road Traffic Safety Directorate (CSDD), cybersecurity expert Elviss Strazdiņš says the key question is not who attacked, but where the stolen data will end up. He does not rule out that a state hostile to Latvia could be behind the breach, but notes that even if the attacker was someone else, the data could still be bought on the black market by anyone, including Russian fraud networks.

Forgotten systems as the weak link

Strazdiņš says he was aware of several vulnerabilities in CSDD's systems that were later fixed, but cannot rule out that one remained unpatched and was exploited. He explains that attackers most often target abandoned or forgotten systems that institutions consider unimportant — yet these are typically the first ones hackers exploit.

Data can circulate for years

According to Strazdiņš, stolen data can remain in use for many years. Victims of fraud have contacted him saying scammers addressed them by their maiden name, even though the woman in question had been married for three years — evidence that outdated records can persist in databases for a long time. He says the black market has no regulation: anyone willing to pay can access the data. Those who steal the data are typically not the same people who commit fraud with it — instead, so-called data brokers buy and resell it to scammers.

Possible fraud schemes

Scammers could use the data to send personalized text messages, for instance citing a vehicle's registration number and an alleged traffic violation, while disguising the sender as CSDD. The only telltale sign of fraud is that the link leads not to CSDD's official website but to a lookalike fake page. Strazdiņš believes financial gain, not reputation-building, is the main motive behind such attacks.

Background on the breach

On Tuesday, Deputy Head of cyber incident response body Cert.lv, Varis Teivāns, revealed that the stolen data came from CSDD payment records spanning the past 18 years. The attack occurred on the night of August 8, but CSDD only reported it to Cert.lv on the evening of August 10. Teivāns explained that Cert.lv had no visibility into this infrastructure because CSDD had earlier opted out of its services. Prime Minister Andris Kulbergs has not ruled out that another country could be behind the attack.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category