A cyberattack on Latvia’s Road Traffic Safety Directorate (CSDD) resulted in the theft of personal data belonging to 1.2 million individuals and data relating to approximately 200,000 legal entities, Varis Teivāns, deputy head of the national cybersecurity incident prevention institution CERT.LV, told journalists today.
The data was obtained from records of payments made to the Directorate over the past 18 years.
Prime Minister Andris Kulbergs (AS) told journalists that he could not rule out the possibility that the cyberattack against Latvia had been carried out by another state, as the specific attacker has not yet been identified.
CSDD and CERT.LV are warning the public about potential fraud risks and urging people to exercise particular caution when receiving messages, emails or phone calls that appear to come from CSDD or other institutions.
Residents are advised to pay attention not only to the content of such messages but also to the quality of the language and spelling, particularly how names, addresses and other personal data are presented. People are also advised not to open links contained in suspicious messages or emails and instead to verify current information regarding CSDD communications via the e-CSDD portal or the CSDD mobile application.
Teivāns stressed that the incident occurred during the night of Saturday, the 8th of August,
but CSDD did not notify CERT.LV until the evening of Monday, the 10th of August, which he said could be explained by the fact that the incident occurred over the weekend. However, he stressed that CERT.LV had no visibility into this infrastructure because CSDD had chosen not to use CERT.LV’s services.
“This was justified on the basis of CSDD’s own capabilities, which meant that early detection from the state’s perspective was not possible,” Teivāns explained.
He said the cyberattack was made possible by a vulnerability in a CSDD information system accessible via the internet. The vulnerability had not been fixed and, according to currently available information, had not previously been detected.
Teivāns said the investigation had established that several requirements set by the Cabinet of Ministers had not been met. For example, Class A systems are required to undergo penetration testing and use multi-factor authentication.
The leaked records include personal identification numbers or company registration numbers,
individuals’ names and surnames or company names, payment amounts, payment dates, vehicle registration numbers, and addresses registered on the date the service was provided, such as the address listed on a vehicle registration certificate.
“No payment information, such as bank account details or other information that would pose an immediate threat to the public, for example through direct financial losses, has been identified. However, there are still risks associated with this information falling into the hands of attackers,” he added.
As an example, Teivāns warned that particular caution should be exercised with authentication solutions such as eParaksts and Smart-ID, where a person’s identification number is often used as the username. Residents should therefore pay close attention if an authentication request appears on their mobile device that they did not initiate.
“There is no immediate threat of further data leaks,
but a risk could arise if fraudsters attempt to authenticate themselves on your behalf, for example in e-CSDD or other systems. If you receive such a request, pay close attention to it. If you did not initiate the authentication process yourself, do not approve it,” he stressed.
Kulbergs said the situation was much more serious than it had previously been portrayed. He acknowledged that he had only learned the following Wednesday, from the head of Latvia’s Constitution Protection Bureau (SAB), about the cyberattack CSDD experienced.
The prime minister also said he believed insufficient lessons had been learned from the case involving state-owned forestry company Latvijas valsts meži (LVM), which had also recently suffered a major cyberattack.
“Instead of providing solutions to this problem as quickly as possible, we are trying to cover our tracks and protect ourselves, despite the fact that this is Class A infrastructure that must be treated with the highest level of responsibility,” Kulbergs said.
He described the CSDD incident as another example of a problem being allowed to escalate
and of irresponsible handling of residents’ data. Kulbergs said that neither in the LVM case nor in the CSDD case should a lack of funding or specialists be accepted as an excuse, arguing that both organisations had apparently taken a highly negligent approach to cybersecurity.
Kulbergs also stressed that this was the second serious cyberattack in the past two months.
The prime minister added that there was one significant difference between the attacks on LVM and CSDD. In the CSDD case, the attacker has not identified themselves, and the stolen data has not appeared publicly.
“As a result, we cannot rule out the possibility that this was a hybrid attack – an operation carried out by another state, a state hostile to us,” the prime minister said.
Latvian authorities are actively monitoring the situation.
“This could potentially be classified as an attack on our country’s critical infrastructure,” Kulbergs said.
He revealed that the Crisis Management Centre has now been designated as the authority responsible for managing the aftermath of the attack together with CERT.LV and CSDD. A dedicated working group will be established for this purpose.
CERT.LV and SAB will also be required to deploy monitoring sensors across Class A infrastructure.
“For four months, CERT.LV worked with CSDD to conclude an agreement on installing such sensors. For reasons we do not understand, CSDD chose not to take this route,” Kulbergs said.
A 12-point resolution issued by the prime minister also stipulates that CERT.LV sensors – monitoring tools capable of automatically detecting unusual activity outside normal operating patterns – must be installed on all Class A infrastructure.
Kulbergs also stressed that the law requires Class A infrastructure to use two-factor authentication,
but this was not in place at CSDD.
The Ministry of Defence has been instructed to amend the relevant Cabinet regulations to make CERT.LV services mandatory for all critical infrastructure. The ministry has also been tasked with establishing a 24/7 national cybersecurity centre.
“At present, such a cybersecurity centre exists, but, to be frank, it exists more on paper than in real life,” Kulbergs said.
He also expressed the view that CSDD’s Management Board and Supervisory Board should bear full responsibility for the incident. He has therefore instructed the transport minister to assess whether members of CSDD’s Management Board and Supervisory Board remain suitable for their positions.
As previously reported, CSDD suffered a sophisticated cyberattack in August,
during which attackers managed to gain partial access to the Directorate’s information technology (IT) systems and obtain historical payment receipt data relating to services provided by CSDD, the Directorate told LETA.
The information obtained by the attackers also contained certain personal data, including personal identification or registration numbers, names and surnames or company names, payment amounts, payment dates, vehicle registration numbers and addresses.
CSDD and CERT.LV are therefore urging residents to exercise particular caution when receiving emails, text messages or other communications that appear to have been sent on behalf of CSDD. In such cases, people are advised to verify the authenticity of the message and check the information directly through e-CSDD.
CSDD is a state-owned joint-stock company. The Directorate registers vehicles in Latvia, issues driving licences, conducts vehicle roadworthiness inspections and provides other services. Its shares are held by the Ministry of Transport.
Read also: Another Company Identified in Latvijas valsts meži Cyberattack Investigation
