Latvia has a population of roughly 1.8 million. This one breach touched records for 1.2 million of them.
A single exposed system, eighteen years of records
CSDD, Latvia’s road traffic safety authority, disclosed on August 18 that attackers had accessed historical payment-receipt data going back to 2008, covering more than 1.2 million individuals and 200,000 businesses and other legal entities. The stolen records include personal identification numbers or company registration numbers, names, payment amounts and dates, vehicle registration numbers, and the address on file at the time each service was received, exactly the combination of identifiers that makes targeted phishing and identity fraud straightforward. CERT.LV, Latvia’s national computer emergency response team, said the attack exploited a vulnerability in a CSDD system that was reachable from the internet, and that the intrusion itself took place over the weekend of August 8-9, meaning the gap between compromise and public disclosure ran to roughly ten days.
The political fallout has already started
The scale and the delay have combined to make this more than a technical incident. Latvia’s president has asked whether the breach amounts to a threat against critical state infrastructure, a criminal investigation is underway, and officials have resigned over the handling of the response. CERT.LV has separately warned that criminals could use the stolen payment and identity data in social engineering and fraud schemes targeting the affected individuals directly, which means the exposure window is not closed just because the system has presumably now been patched.
The lesson is not really about Latvia
An internet-facing government system holding registry-scale personal data is an extreme version of a pattern that applies just as directly to a private company’s customer portal, partner API or public booking system: any service reachable from the outside world is a service an attacker can find and probe without needing to be inside your network first. GDPR’s 72-hour breach notification clock and NIS2’s incident reporting obligations exist precisely because the interval between compromise and disclosure matters, both for the people whose data was taken and for the organisation’s own legal exposure. A ten-day gap between an internet-facing system being compromised and the public finding out is the kind of delay that draws exactly the scrutiny CSDD is now getting.
What this should prompt you to check
If your organisation runs any system that is reachable from the public internet and holds personal, financial or identity data at scale, a fresh review of that system’s patch status, exposure surface and monitoring coverage is worth doing now, not at the next scheduled audit. Confirm your breach notification process can actually meet the GDPR 72-hour window if the worst happens, because a plan that only exists on paper tends to fail exactly when the ten-day gap is being decided.
If you want an external review of your internet-facing systems, or help building an incident response and breach notification process that holds up under real pressure, contact Excello Digital. We help European organisations find the exposure before an attacker does, and respond properly when they don’t.
