Data security incident hits Latvia’s Consumer Rights Protection Centre – hundreds of people affected

A data security incident has been detected in one of the information systems managed by Latvia’s Consumer Rights Protection Centre (PTAC), the authority said.

The affected system is the Remote Statistical Data Retrieval System (ASDIS). ASDIS is classified as a Class C security system, the lowest risk level for information systems. PTAC uses the system to supervise licensed businesses, and it complies with Latvia’s minimum cybersecurity requirements.

ASDIS is hosted on network infrastructure equipped with an early warning sensor system operated by Latvia’s cybersecurity incident response institution CERT.LV.

The investigation so far indicates that the incident resulted in the extraction of contact information relating to entities licensed by PTAC, including consumer credit providers, out-of-court debt collection service providers and package travel service providers.

The compromised data includes the contact details of representatives of 697 businesses and 34 PTAC officials – names, surnames, email addresses and telephone numbers. In most cases, this information is also available in other public registers, such as Latvia’s Open Data Portal.

The incident did not compromise supervisory data submitted to PTAC by businesses.

The affected system has currently been shut down. PTAC has also informed all users that the system is unavailable.

PTAC noted that, given the unstable geopolitical situation, it is essential to strengthen the security of all technological resources and allocate the necessary funding. The Ministry of Economics has previously highlighted this issue during a Cabinet meeting on cybersecurity.

Read also: BNN IN FOCUS | Four years, three governments and the same old problems: where does Latvia stand ahead of the election?

Seko mums arī FacebookDraugiem un X