Latvia's cybersecurity threat level remains high. CERT.LV reported 673 manually processed cyber incidents in the second quarter of 2026. Although this was 20% lower than in the previous quarter, both incident and compromised-device indicators remain significantly above the 2022–2024 average.
Two major incidents attracted particular attention during the summer: the attack against AS “Latvijas valsts meži” and the August cyberattack against the Road Traffic Safety Directorate, CSDD. They demonstrate why a data breach is not merely an IT problem: stolen information can later become the foundation for highly personalised fraud.
What data was actually obtained in the CSDD cyberattack?
On 18 August 2026, CSDD announced that between 8 and 10 August an attacker had unlawfully obtained historical payment receipt information dating back to 2008. Data relating to approximately 1.2 million individuals and 200,000 legal entities was affected.
The affected categories include:
- personal identity number or company registration number;
- name and surname or company name;
- payment amount and payment date;
- vehicle registration number;
- the address registered when the relevant service was received.
CSDD customer telephone numbers and email addresses were not affected. Customer usernames and passwords were also not compromised. A personal identity number alone does not provide access to Smart-ID, eParaksts mobile, online banking or other authenticated services.
What could criminals theoretically do with this combination of data?
The following examples are not confirmed consequences of the CSDD incident. They are realistic social-engineering scenarios illustrating how stolen information could potentially be combined with publicly available data and artificial intelligence tools.
1. A fake speeding fine with an AI-generated “speed camera image”
If a criminal knows a person's name, address and vehicle registration number, these details could be combined with information obtained elsewhere. Generative AI could theoretically be used to produce a convincing image of a vehicle, an imitation speed-camera photograph or a document showing a registration number, date and alleged traffic violation.
The victim could receive a personalised “fine notice” containing genuine personal details and the correct vehicle registration number while the payment link leads to a fraudulent website. Combining real data with fabricated visual evidence could make such a scam considerably more convincing.
2. A fake technical inspection, tax or CSDD payment correction
Knowledge of a previous payment amount and date can make a fraudulent message appear connected to a genuine transaction, for example by claiming that there is an unpaid difference, a payment error or a requirement to make an additional payment.
3. “You are entitled to a refund”
Fraud does not always ask the victim to pay. A message claiming that a CSDD overpayment is being refunded may be equally effective. The victim is directed to a fake authentication or banking page supposedly to receive the money.
4. Highly personalised fake invoices targeting businesses
A company's name, registration number, vehicle registration number and historical payment information could help criminals produce a convincing payment request for an accounting department. The risk increases when the leaked information is combined with publicly available information about company managers, employees or contact persons.
5. Smart-ID and eParaksts mobile social engineering
A Latvian personal identity number alone does not provide access to digital services, but it may be used as an identifier during an authentication process. A criminal may attempt to initiate authentication and persuade the victim to approve the request.
If you receive a Smart-ID or eParaksts mobile authentication request that you did not initiate yourself, do not approve it.
Why does artificial intelligence make fraud more dangerous?
Previously, phishing attempts were often exposed by poor language, primitive design or obviously fake documents. Generative AI can now produce polished text, documents, images, audio and other content within seconds.
The security rule is therefore changing: a message should not be trusted simply because it looks professional or contains accurate personal information.
What should you do after the CSDD data breach?
1. Find out whether your data was affected
CSDD states that every person has the right to request information on whether their personal data was affected and which categories were involved. The procedure is described in CSDD's Privacy Policy.
2. Verify CSDD information only through official channels
If you receive an unexpected SMS, email or payment request, do not use the link contained in the message. Open e.csdd.lv manually or use the official CSDD mobile application.
3. Never approve unexpected authentication requests
If you did not initiate a Smart-ID or eParaksts authentication yourself, do not approve it regardless of what a caller or message claims.
4. eParaksts mobile users should check their user number
CSDD and CERT.LV advise eParaksts mobile users to check whether their user number is their personal identity number. If it is, users may consider replacing it with a randomly generated seven-digit number.
5. Businesses should verify payment details independently
If an unexpected invoice arrives or bank account details have changed, do not approve payment solely on the basis of the email. Compare the information with previously verified documents or confirm the change using an independent communication channel.
6. Use the CERT.LV DNS Firewall
The CERT.LV DNS Firewall is a free security service for internet users and organisations in Latvia. It helps block access to phishing, malware and other malicious websites identified by CERT.LV.
Latvijas valsts meži also suffered a major cyberattack
On 22 June 2026, a large-scale cyberattack was identified against the IT infrastructure of AS “Latvijas valsts meži”. A financially motivated foreign ransomware group claimed responsibility. CERT.LV reported that approximately 44 GB of information had been leaked, while the total amount potentially obtained by the attacker could have been larger.
The incident also highlighted an important lesson for organisations: a single unpatched vulnerability in a publicly accessible system can become the entry point for a much broader attack.
Frequently asked questions
Do I need to change my e-CSDD password?
CSDD states that customer usernames and passwords were not affected. Nevertheless, unique passwords and multi-factor authentication remain recommended for other accounts.
Can someone access Smart-ID using only my personal identity number?
No. A personal identity number alone does not provide access to Smart-ID or eParaksts mobile. The danger arises if the victim approves an authentication request initiated by a criminal.
Does seeing my real vehicle registration number prove that a message came from CSDD?
No. Following a data breach, the use of genuine identity or vehicle information is no longer evidence that a message is authentic. Always verify the information independently through the official service website or application.
The key takeaway
After a major data breach, the greatest risk is not merely that information has been stolen, but that it can be combined with other data and used for highly personalised social engineering. Artificial intelligence can make this process faster and more convincing.
If a message contains your real name, identity number or vehicle registration number, that does not prove that the sender is who they claim to be.
Comments
No comments yet. Yours could be the first!
Add a comment