Data Breaches

Latvia’s CSDD Board Resigns After Its Monitoring Provider Missed the Breach

Latvia’s CSDD Board Resigns After Its Monitoring Provider Missed the Breach

The entire management of Latvia’s Road Traffic Safety Directorate resigned on Wednesday, six days after the agency disclosed that attackers had taken payment records covering 1.2 million people. Latvia’s population is just over 1.8 million.

The directorate known by its Latvian initials CSDD, registers vehicles and issues driving licences. It says the intruders were in its systems between 8 and 10 August and pulled data from payment receipts going back to 2008, personal identity codes or company registration numbers, names, payment amounts and dates, vehicle number plates and the address on file at the time each payment was made. Records for 200,000 companies and other legal entities were taken as well. Customer phone numbers, email addresses and passwords were not affected.

CSDD did not learn any of this from the company it pays to monitor its infrastructure. Its own IT staff found the intruders.

Tet Held the Monitoring Contract and Saw Nothing

Outgoing CSDD chief Aivars Aksenoks told Latvian Television that the Latvian telecoms and technology group Tet supplies the directorate’s IT infrastructure along with firewall management, continuous monitoring and incident escalation. Across the Saturday and Sunday when the attack ran he said, Tet sent no alert and had detected nothing. Nobody knew, in his words, “even though it was their responsibility”.

CSDD’s own technicians noticed the unusual activity, traced it to several IP addresses and blocked them within a few hours. The data theft was not apparent at that stage. When CSDD contacted Tet on the Monday, Tet still had nothing.

Latvia’s electronic procurement records put the original value of the contract Tet won covering IT infrastructure provision and management for the national vehicle and driver register at almost 9 million euro excluding VAT.

Tet chairman Uldis Tatarcuks told Latvian Radio that the system in question is maintained under that contract by Kyndryl working as Tet’s subcontractor. He did not deny that Tet carries responsibility. His account of the detection failure is that the attack was professional and targeted and therefore hard to see. Tet has since revised its monitoring thresholds and run a deeper analysis of systems and log files and says the adjustment has already surfaced suspicious activity the company was able to act on.

Aksenoks made the vendor argument on the same morning his own board was being pushed out and that timing belongs in any assessment of it. Tatarcuks did not contest the substance. The dispute is over how responsibility divides not over whether the monitoring worked.

CERT.LV Found Missing Basics, Not an Exotic Adversary

CERT.LV, Latvia’s national incident response institution, said the attackers exploited a vulnerability in a CSDD system that was reachable from the internet, that several mandatory cyber security requirements had not been met and that word of the incident reached it late. Varis Teivans, deputy head of CERT.LV, described the attack as targeted, prepared in advance and indicative of technical competence on the attackers’ part.

Both findings hold at once and the second carries less weight than it first appears to. An internet-facing system with an exploitable flaw and unmet baseline requirements is not a puzzle that needs an elite adversary to solve. Read “targeted and technically competent” as a description of who came through the door not as an explanation of why the door opened.

The two organisations also disagree over whether CSDD had declined CERT.LV’s services. Aksenoks rejected that account saying a CERT.LV employee had sent a draft agreement to a CSDD security specialist who asked follow-up questions and never received a reply and that the board saw none of the correspondence. He said he signed and sent the agreement on Tuesday.

Transport Minister Rihards Kozlovskis has ordered an expedited internal investigation into the circumstances, the individuals responsible and the Tet contract itself. The Prosecutor General’s Office is examining the liability of CSDD officials. The State Police have opened criminal proceedings, the State Chancellery’s Crisis Management Centre has been instructed to form a working group with CERT.LV and CSDD has notified the Data State Inspectorate under GDPR.

The Personal Identity Code Is the Dangerous Part

CERT.LV assesses the practical risk as social engineering. A caller who already has your name, personal identity code, number plate, address and the amount and date of your last payment to CSDD does not sound like a stranger.

The identity code is the sharper problem. Latvians use it as the user number for Smart-ID and eParaksts mobile when signing in to services including Latvija.gov.lv, e.csdd.lv, the health portal E-veseliba and the tax portal EDS. The code by itself unlocks nothing. It does let a fraudster trigger an authentication prompt on your phone in the hope that you approve it without thinking.

CERT.LV’s instruction runs to one line: never approve a Smart-ID or eParaksts mobile authentication request you did not start yourself.

eParaksts mobile users have a further step available. Accounts opened since April 2022 default to the personal identity code as the user number. Look yours up in the eParaksts mobile app or under Products in your eParaksts.lv profile and change it to a randomly generated seven-digit number if it is currently your identity code.

Telia Holds 49 Percent of the Vendor Now Under Investigation

Tet is 51 percent owned by the Latvian state through the asset manager Possessor and 49 percent by Tilts Communications, a wholly owned subsidiary of Telia Company. Effective control sits on the state side. The Swedish group is nonetheless a shareholder in the supplier whose incident monitoring a Latvian minister has just placed under formal review.

Telia is on its way out. It signed a memorandum of understanding in July 2025 to sell its holdings in Tet and mobile operator LMT to the Latvian state, Latvenergo and LVRTC, with an international investor to join afterwards. The timetable has moved more than once and the transaction was still open in July 2026.

The transferable detail for Nordic buyers is not the ownership. It is that a monitoring arrangement of that size produced no alert across a three-day exfiltration and that the customer found out from its own staff.

Three Questions Before Your Next Monitoring Invoice

Ask what your provider’s weekend and out-of-hours escalation actually consists of, expressed in named roles and response times rather than service descriptions. Tet’s monitoring covered the weekend on paper.

Ask where the detection thresholds sit and when they were last reviewed. Tet revised its thresholds after this incident and promptly began catching activity it had not been catching before. That sequence says something about where the thresholds had been.

Ask who performs the work. CSDD contracted Tet. Tet subcontracted Kyndryl. Where operational responsibility actually sat became clear in public only after the directorate’s entire management had resigned.

References

  1. Latvian Officials Resign After Cyberattack Exposes Data on 1.2 million People
  2. Noslēgusies CSDD kiberincidentā izgūto datu analīze
  3. CSDD saskāries ar kiberdrošības incidentu
  4. CSDD vadītājs Aksenoks pēc kiberincidenta izmeklēšanas gatavs atkāpties no amata
  5. Izmeklēšanā vērtēs arī CSDD līgumu ar Tet, uzņēmums nenoliedz savu atbildību
  6. Latvenergo and LVRTC Sign Memorandum of Understanding with Telia Company on Acquisition of Shares in Tet and LMT
  7. 23 Investors Compete for LMT and Tet as Latvia Nears Landmark Telecom Deal

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.