Decoding the world of cybersecurity

·

Latvia arrests suspect over company cyberattacks

Latvian police have arrested a man suspected of attacks against at least two companies involving alleged unauthorised database access, personal-data extraction, and attempted extortion.

Latvia arrests suspect over company cyberattacks
Summary
  • Latvian State Police arrested a man born in 2003 on suspicion of cyber offences involving at least two companies.
  • Police allege automated tooling was used to identify a website vulnerability, extract database information, and demand payment to prevent disclosure.
  • Evidence seized during the investigation may relate to further attacks in Latvia and abroad, but those cases remain under investigation.

Latvian State Police have arrested a man suspected of carrying out cyberattacks against at least two companies for financial gain, including an incident in which personal data was allegedly extracted and payment demanded to prevent its disclosure.

The suspect, a man born in 2003, was detained on 15 September following an investigation by the police cybercrime unit. He has been formally treated as a suspect in two criminal investigations, but no guilt has been established and the cases remain under investigation.

One incident occurred in February. A second, involving what police described as similar characteristics, was detected in early September against TSC, an electronics and smart-device repair business within the LMT group.

Investigators allege the attacker used automated attack tooling to identify a vulnerability in a company website, access the underlying database, and export information that included restricted-access data.

Police say some personal information was obtained and the attacker subsequently used an anonymous email account to demand payment in exchange for not distributing the data.

The force currently believes the information taken in the attacks was not passed to third parties. That remains an investigative finding rather than an independently verified account of every copy or use of the data.

The TSC investigation involved support from LMT’s security service and CERT.LV. Police said analysis of the attack characteristics allowed investigators to connect the September incident with the earlier case and identify a possible suspect.

A search in Riga after the arrest produced evidence and information that investigators say may relate to additional attacks against companies in Latvia and other countries. Those possible links remain under investigation and should not be treated as established offences.

The case is notable because the alleged targeting appears to have relied on automation rather than selection of one strategically valuable company. Police say the tooling was used to identify vulnerabilities across websites and resources.

That model changes the exposure calculation for smaller organisations. A company does not need to be strategically important or specifically selected in advance to attract malicious attention when scanning and exploitation can be applied across many internet-facing systems.

The alleged extortion method also differs from conventional file-encrypting ransomware. Police have described unauthorised database access and a demand for payment to prevent further disclosure, but they have not said that systems were encrypted or that business operations were held hostage through ransomware deployment.

Data theft alone can create substantial leverage when the information has privacy, regulatory, contractual, or reputational sensitivity. Extortion without encryption has consequently become part of the wider cybercrime economy, particularly where attackers can extract information quickly from externally reachable applications.

The Latvian investigation also shows the evidential value of comparing behaviour across incidents that initially appear unrelated. Infrastructure, tools, communication methods, and attack sequences can connect separate victims without establishing that every superficially similar attack has the same source.

International scope remains unresolved here. Although police say seized material may point towards attacks abroad, the investigation has not established the full victim set or legal outcome of those suspected offences.

The confirmed position is narrower: a suspect has been arrested, investigators have linked him to two criminal cases, and the allegations include unauthorised access, extraction of data, interference with information systems, and attempted extortion. The presumption of innocence remains in force while the proceedings continue.

×