How did data on 1.2 million people leak from CSDD? Investigation reveals multiple failures

The data breach at Latvia’s Road Traffic Safety Directorate (CSDD) was facilitated by several shortcomings in cybersecurity management, including inadequate security testing, insufficient network protection, a lack of multi-factor authentication and flaws in software development, according to an assessment carried out by a commission established by the Ministry of Transport.

The Ministry of Transport commission, acting on an order from Transport Minister Rihards Kozlovskis (JV), has completed its assessment of the CSDD cyber incident. Its task was to establish the circumstances surrounding the causes of the incident, assess the effectiveness of its detection and response, and evaluate whether the technical and organisational measures implemented by CSDD were adequate.

The commission has prepared a report summarising its conclusions and recommendations for addressing technical vulnerabilities and strengthening cybersecurity.

Kozlovskis said the assessment shows that several mistakes and failures occurred in CSDD’s cybersecurity management, including, at times, an overly formal approach, which meant that opportunities for a cyberattack were not fully eliminated.

Shortcomings were identified in the procedures

followed both by the organisation’s employees and by external service providers. At the same time, assessing the responsibility of individual officials falls within the competence of law enforcement authorities.

“The task of the internal investigation was to establish the situation and its circumstances and to prepare recommendations for specific measures so that similar risks can be prevented in the future and the data of Latvia’s residents can be kept secure,” Kozlovskis explained.

The commission established by the Ministry of Transport concluded that the incident was made possible by a vulnerability in the CSDD-operated web application “med.csdd.lv”, which allowed the attacker to gain initial access to information systems.

Several technical and organisational shortcomings prevented the vulnerability from being addressed earlier,

including inadequate security testing, insufficient network protection, the absence of multi-factor authentication and flaws in software development.

The investigation also identified the long-term storage of historical personal data, an issue that will be assessed by the Data State Inspectorate.

A cybersecurity control system had been established, but in practice it repeatedly failed to achieve its intended purpose. The commission identified several shortcomings in risk management and cybersecurity governance, including insufficient specialist capacity, an inadequate scope of security testing and audits, and incomplete documentation.

After gaining initial access, the attacker was able to extract large volumes of data over an extended period because

there were insufficient mechanisms for controlling the volume of requests and identifying anomalous activity.

The commission concluded that, regardless of the reason the initial vulnerability emerged, a professional security monitoring service provider would normally be expected to identify and restrict unusual, prolonged data activity in a timely manner in order to prevent large-scale data extraction over an extended period.

After detecting the incident, CSDD fulfilled its statutory reporting obligations to the relevant state authorities within the required deadlines.

The commission’s report lists several recommendations for strengthening CSDD’s cybersecurity. These include addressing the identified cybersecurity and data protection risks, reviewing data retention periods, ensuring sufficient capacity for cybersecurity functions, reviewing and improving the contract with Tet, and introducing a system for managing such outsourced services.

The commission did not assess the possible responsibility of individual CSDD officials,

as this falls within the competence of law enforcement authorities. The assessment report and related materials will be forwarded to law enforcement institutions.

As previously reported, a cyberattack on CSDD in early August resulted in the theft of personal data belonging to 1.2 million people, as well as data relating to approximately 200,000 legal entities. The information was obtained from payments made to the Directorate over the past 18 years.

Following calls from several officials for those responsible to step down, both the CSDD Management Board and Supervisory Board resigned.

Kozlovskis ordered an expedited internal investigation to establish all the circumstances and determine responsibility in connection with the cyberattack and the large-scale data breach. Among other issues, the investigation was also tasked with assessing CSDD’s contract with Tet for the provision of cybersecurity services.

Meanwhile, the Prosecutor General’s Office has launched a prosecutor’s review into possible violations or negligence that may have resulted in the data breach from CSDD information systems.

The State Police have also opened criminal proceedings over the cyberattack on CSDD.

Read also: BNN IN FOCUS | “Arrogant officials don’t understand” – CSDD data leak also poses a threat to democracy