Decoding the world of cybersecurity

CSDD leadership quits after Latvia data breach

Latvia’s road authority has lost its senior leadership after a breach exposed data linked to 1.2 million people and prompted an investigation into its cybersecurity arrangements.

CSDD leadership quits after Latvia data breach
Summary
  • Personal data relating to 1.2 million people and around 200,000 businesses was obtained from Latvia's Road Traffic Safety Directorate.
  • CSDD's board and management board have stepped down, while an urgent internal investigation will examine the attack and outsourced cybersecurity arrangements.
  • The incident has moved beyond breach response into accountability for the resilience of a nationally important public database.

A cyberattack exposing data linked to 1.2 million people has cost the senior leadership of Latvia’s Road Traffic Safety Directorate (CSDD) their positions, turning one of the country’s largest recent data incidents into a wider examination of public-sector cyber governance.

All members of the CSDD board and management board submitted their resignations on Wednesday, 19 August, after Transport Minister Rihards Kozlovskis summoned the organisation’s leadership following the breach. The resignations came a day after CSDD disclosed that attackers had obtained personal data relating to around 1.2 million people — a striking proportion of Latvia’s population — as well as information connected with approximately 200,000 businesses.

The incident began with unauthorised access to CSDD systems earlier in August. Initial disclosures described the compromised information as historical payment and service data. Subsequent investigation substantially increased the known scale of the exposure, including names, vehicle registration information, addresses associated with transactions, and other records held by the authority.

What remains unclear is who carried out the attack, precisely how the intrusion occurred, and the full extent to which individual records can be combined or used beyond their original administrative purpose. CSDD has not publicly attributed the incident to a criminal or state-linked actor.

The leadership departures have also widened the investigation beyond the immediate technical failure. Kozlovskis has ordered an urgent internal inquiry intended to establish the circumstances of the breach and responsibility for the incident. That process will examine CSDD’s contract with Latvian technology company Tet for cybersecurity and IT infrastructure services.

Latvian Public Media reported that a contract concluded in 2022 for infrastructure services supporting the State Register of Vehicles and Drivers had an initial value of €8.989 million excluding VAT. The existence of an outsourced security arrangement does not establish responsibility for the attack, but its inclusion in the inquiry puts supplier governance and contractual accountability alongside questions about CSDD’s own controls.

The authority occupies an unusually sensitive position in Latvia’s digital public infrastructure. It maintains the country’s vehicle and driver registers and provides vehicle registration, driver licensing, technical inspections, and related electronic services. Large administrative databases of this kind accumulate value because information collected for routine public services can create a detailed picture of individuals and organisations when extracted at scale.

That makes the eventual findings of the investigation more important than the departure of individual executives. Public agencies increasingly depend on combinations of internal systems, external infrastructure operators, security suppliers, and long-running databases whose sensitivity grows as records accumulate. Accountability becomes difficult if responsibility for detection, access control, monitoring, and incident escalation is fragmented across those relationships.

The attack has also demonstrated how the severity of an incident can change during investigation. CSDD first disclosed partial access to historical information, before later confirming a dataset affecting a substantial majority of Latvia’s adult population. That progression places pressure on incident-response processes not only to contain an attacker, but to establish quickly what information was actually taken and communicate the changing picture accurately.

CSDD’s services have continued while investigations proceed. Latvia now has to determine whether the breach resulted primarily from a specific technical weakness, failures in operational security, shortcomings in supplier oversight, or a combination of those factors. With both senior governing bodies gone, the answer will shape how responsibility for one of the country’s most important public data systems is rebuilt.

×