On the 15th of September, Latvian State Police arrested a hacker born in 2003 on suspicion of carrying out cyberattacks against at least two Latvian companies for financial gain.
One attack against a company was recorded as early as February this year, while another cyberattack with a similar modus operandi was detected in early September against household appliance and smart device repair company TSC, which is part of the LMT group, the State Police reports.
The hacker gained unauthorised access to some of the personal data stored in the database and attempted to extort money in exchange for not disclosing the data further. Information available to the State Police indicates that the suspect did not distribute the data obtained in the cyberattacks.
In both cases, the man born in 2003 has been formally recognised as a suspect, and investigations in the criminal proceedings are continuing.
While investigating criminal proceedings concerning a cyberattack on a company’s website in February this year, the First Division of the State Police Cybercrime Combating Department analysed the nature of the attack and the attacker’s “modus operandi”, which indicated a connection to the recent attack on the TSC website.
Investigators established that the suspect used an automated attack tool to identify a vulnerability,
after which he gained access to the website’s database and exported information, including restricted-access data.
The attack was carried out using virtual masking tools to conceal the attacker’s actual location. After completing the attack, the hacker contacted the company using an anonymous email account created specifically for this purpose and demanded payment in exchange for not distributing the stolen data further.
By analysing and investigating the cyberattack on the TSC website, with support from the LMT Security Service and CERT.LV, investigators were able to quickly establish and verify the circumstances of the case. This enabled the State Police not only to identify a potential suspect, but also to link the two incidents and determine the suspected hacker’s location.
On the 15th of September, law enforcement officers arrested the hacker, a man born in 2003, and carried out several other procedural actions, including a search at an address in Riga.
During the investigation, police obtained evidence and information concerning other cyberattacks
allegedly carried out by the suspect against various companies in Latvia and abroad. Investigations into these incidents are continuing.
Based on information obtained during the investigation, there are grounds to believe that, thanks to the swift action of the State Police, the personal data obtained without authorisation was not passed on to third parties.
The First Division of the State Police Cybercrime Combating Department succeeded in linking the two cases, and the detained man has been formally recognised as a suspect in both criminal proceedings.
The cases are being investigated under Section 241, Paragraph two of the Criminal Law for unauthorised access to an automated data processing system for financial gain; Section 183, Paragraph one for extortion; and Section 243, Paragraph three for disrupting the operation of an automated data processing system and unlawfully handling information contained in such a system for financial gain.
In investigating the suspect’s motives, police established that the cyberattacks did not target specific companies. Instead, automated attack tools were used to scan various websites and online resources in search of vulnerabilities.
The State Police therefore urges all companies to assess their online resources and ensure that appropriate security measures are in place to minimise the risk of similar incidents occurring in the future.
Read also: How did data on 1.2 million people leak from CSDD? Investigation reveals multiple failures
