Latvia's road traffic safety directorate, CSDD, says attackers reached the payment receipt data it holds on roughly 1.2 million people and 200,000 organisations. The records run back to 2008.
Latvia has a population of under two million.
Eighteen years of payment receipts
In a notice on its own website, CSDD says its information systems suffered unauthorised access in August, and that what the attackers obtained is the historical payment information contained in CSDD payment receipts, spanning 2008 to 2026. Payment receipts are the trail of routine transactions with a national road authority, and eighteen years of them is a very wide net in a country this size.
Check Point Research's weekly threat intelligence bulletin, published the same day, records the stolen fields as identification numbers, licence plates, payment amounts, dates and addresses, and puts the figure at roughly two thirds of the country's population. CSDD's own notice does not itemise the data categories.
What CSDD is not saying
The agency does not disclose how the attackers got in. It says the access channels used in the attack have been identified and blocked, that CERT.LV and law enforcement are investigating, and that its services continue to run normally. Check Point's bulletin says attackers reportedly exploited a vulnerability in an internet-facing system, which CSDD has not confirmed.
No group has claimed the intrusion publicly, and no timeline has been published for when the access began or how long it went unnoticed. CSDD does say the data it holds was not deleted or corrupted, and that it sees no reason for people to stop using its services.
The follow-on risk is the phone call
CSDD's public advice is aimed squarely at what comes next rather than what already happened. It is warning people to be careful with messages and calls that appear to come from CSDD or another institution, not to act on links inside them, and to verify anything through the official portal or the CSDD app. Its sharpest instruction is the one worth repeating: never approve a Smart-ID or eSignature request you did not start yourself.
That advice follows the shape of the data. Someone holding your identification number, your licence plate, and the amount and date of a payment you genuinely made has a script that already sounds authentic before they ask you for anything. The value of a leak like this to a fraudster is less the data itself than the credibility it buys.
A second hard year for Latvian institutions
The country's cyber posture and incident history sit on our Latvia profile. In July a ransomware crew reached Latvijas Valsts mezi, the state forestry company, through a flaw that had been patchable for two years. This one is larger by every measure that counts, and unlike that intrusion it touches the general public directly.
The full CSDD notice is published on the agency's site in Latvian, and the corroborating entry appears in Check Point Research's 24 August threat intelligence report.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.