Skip to content
Vulnerability exploitContained

Latvia CSDD vehicle-registry data breach

An attacker exploited an unpatched, internet-facing system at Latvia's Road Traffic Safety Directorate (CSDD) to steal historical payment and vehicle records covering roughly 1.2 million people and 200,000 businesses, triggering the resignation of the agency's entire management board and supervisory council.

Victim
Ceļu satiksmes drošības direkcija (CSDD)
records
1.2M
users
1.2M

On 18 August 2026, Latvia's Road Traffic Safety Directorate — the state agency known by its Latvian initials CSDD, which runs vehicle registration, driver licensing and roadworthiness testing — confirmed that a cyberattack had exposed personal data on roughly 1.2 million people and 200,000 businesses and other legal entities, a figure equivalent to a large share of the country's population. The stolen records were historical payment receipts and related vehicle data reaching back to 2008.

According to CSDD and Latvian reporting, an attacker broke into an internet-facing CSDD system overnight between 7 and 8 August 2026 by exploiting a vulnerability that, by the agency's own account, had never been patched and had gone undetected. The stolen records can include a person's name, Latvian personal identification number, vehicle registration plate, payment information and the address recorded when a CSDD service was provided.

What happened

The breach drew heavy criticism not only for its scale but for the agency's handling of it. The initial intrusion occurred during the night of 7-8 August, yet CSDD did not notify the national cybersecurity authority CERT.LV until 10 August, and it was only on 18 August that the directorate stated publicly that data on 1.2 million people had been taken. Investigators later described a chain of failures — an unpatched, exposed system and delayed detection and disclosure — behind the incident.

The fallout was swift. On 19 August 2026, CSDD's management board and supervisory council both resigned, and President Edgars Rinkēvičs referred the conduct of CSDD officials to the prosecutor general. The case has been widely cited as an early test of accountability and incident-reporting obligations under the EU's NIS2 directive.

Impact

  • Personal and vehicle records for approximately 1.2 million individuals and 200,000 businesses were exposed, spanning receipts and service data back to 2008.
  • Exposed fields include names, national identification numbers, licence plates, payment details and addresses — a combination well suited to identity fraud and targeted scams.
  • The breach forced the resignation of CSDD's entire governing leadership and a referral to prosecutors over the agency's response.

Why it matters

The CSDD breach is a textbook illustration of how a single unpatched, internet-facing system in a public registry can compromise a substantial fraction of a nation's citizens at once. Because motor-vehicle authorities concentrate durable identifiers — national ID numbers tied to names, addresses and plates — a single lapse yields a data set that stays useful to fraudsters for years. The leadership resignations and prosecutorial referral also underscore that, under NIS2, delayed detection and reporting now carry direct governance consequences for essential-service operators.

Timeline

  1. An attacker breaks into an internet-facing CSDD system overnight, exploiting a vulnerability the agency says had never been patched.

  2. CSDD notifies the national CERT.LV of the intrusion, days after the initial access.

  3. CSDD publicly reports that personal data on roughly 1.2 million people was obtained in the cyberattack.

  4. CSDD's management board and supervisory council resign; the president refers the officials' conduct to the prosecutor general.

Sources

  1. therecord.mediahttps://therecord.media/latvia-cyberattack-vehicle-data
  2. cybernews.comhttps://cybernews.com/security/latvia-csdd-cyberattack-personal-data-stolen/
  3. eng.lsm.lvhttps://eng.lsm.lv/article/society/crime/18.08.2026-data-of-12-million-people-breached-in-recent-csdd-cyberattack.a659333/
  4. eng.lsm.lvhttps://eng.lsm.lv/article/society/crime/19.08.2026-csdd-boss-ready-to-quit-over-massive-database-leak.a659407/

Related incidents