Latvia’s road-traffic agency just told the country that hackers walked off with payment-receipt data covering about 1.2 million people — roughly two-thirds of the population — plus about 200,000 businesses. The Road Traffic Safety Directorate (CSDD) confirmed the scale on August 18, 2026, after a cyberattack over the weekend of August 8–9. Primary reporting: The Record and LSM. Canonical row: latvia-csdd2026.
This is not a niche municipal leak. National ID numbers, vehicle plates, payment history back to 2008, and registration addresses are now in attacker hands. President Edgars Rinkēvičs called it a significant national-security threat. The supervisory board resigned. The agency chief said he would step down after stabilizing the response.
What happened in the Latvia CSDD data breach
CSDD first disclosed a “complex” cyberattack the week of August 13, saying third parties gained partial access to systems holding historical payment receipts. CERT.LV later told local media attackers exploited an internet-exposed vulnerability and that several mandatory cybersecurity requirements had not been met. CSDD staff — not the contracted monitor — discovered and stopped the intrusion within hours, according to agency leadership.
On August 18, after analyzing what left the building, CSDD put numbers on the table: more than 1.2 million natural persons and about 200,000 legal entities. Services stayed online. A follow-on attack attempt the next weekend was blocked after hardening, the agency said.
What data was exposed
Per CSDD’s public inventory, stolen receipt-era fields include:
- Personal identification number (Latvia’s national ID) or company registration number
- First name and surname, or company name
- Payment amount and payment date
- Vehicle registration (license plate) number
- Address listed when the service was received (e.g., address on the vehicle registration certificate)
CSDD says customer phone numbers and email addresses were not compromised, usernames and passwords were not taken, and address fields were incomplete in some records. That carve-out helps — it does not erase the social-engineering power of a national ID plus plate plus old payment date.
What was not exposed (per CSDD)
Phone numbers, emails, and portal credentials stayed out of the stolen set, according to the agency. Day-to-day e-CSDD and in-person services continued. The public vehicle look-up-by-plate feature was restricted after the incident so strangers could not pull make/model as easily from a plate alone.
How the attack worked
Public detail is still thin on the exact CVE or exploit chain. CERT.LV described a prepared, targeted intrusion against an internet-facing CSDD system. Leadership pointed at gaps in mandatory cyber controls and at monitoring coverage under a contract with telecom/IT firm Tet — which pushed back, saying investigators must map which systems failed before assigning blame. State police opened criminal proceedings; the Data State Inspectorate was notified.
Who is at risk
Almost anyone who paid CSDD for a road-related service since 2008 — vehicle owners, drivers renewing documents, companies with fleets. Diaspora Latvians who kept a registered vehicle or address on file. Small businesses whose registration numbers and payment history now sit beside personal IDs of their owners. Even people with incomplete address rows still have ID + plate combinations useful for fraud scripts.
CERT.LV’s warning is blunt: names, personal codes, plates, addresses, and prior payment details make SMS and call scams far more believable. Expect “CSDD fine unpaid — pay here” and “your vehicle registry is locked after the cyberattack” lures that cite a real plate.
Political and institutional fallout
Rinkēvičs said CSDD management should not continue. Parliament voices echoed that. The supervisory board resigned; an interim board followed. Director Aivars Aksenoks said he would leave after helping finish the investigation — “I can’t just slam the door.” The episode sits beside an earlier 2026 ransomware hit on state forestry company LVM, keeping Latvian state IT under a harsh spotlight.
Industry context
National vehicle registries concentrate immutable identifiers. A breach here is closer to a population-scale identity event than a retail email dump. Compare scale — not methods — to other 2026 government catalog rows such as Liechtenstein’s AML register hack or large electoral claims elsewhere. Latvia already has a painful municipal IT precedent in the older ZZ Dats fine case; CSDD is a different agency and a much larger population share.
What CSDD and CERT.LV said people should do
Official guidance stresses verifying messages against e.csdd.lv or the CSDD mobile app — not links in texts. Watch spelling and odd payment URLs. Treat unexpected “registry unlock” or “refund” messages as hostile. CSDD continues cooperating with investigators and restricted plate-based vehicle lookups.
Action items
- Assume your personal code and plate may be known to fraudsters if you used CSDD services since 2008.
- Never pay a “CSDD fine” from an SMS link; use only official e-CSDD or the app.
- Hang up on callers who recite your plate and demand card details “to secure your registry after the breach.”
- Monitor bank accounts for unfamiliar card checks timed to fake government payments.
- If you run a fleet company, brief staff that vendor emails citing exact historical payment amounts may be forged.
- Keep government portal passwords unique; CSDD says those hashes were not in this haul, but credential-stuffing still thrives after any national headline.
- Parents and caregivers: warn older relatives who still answer unknown numbers about plate-personalized scripts.
- Bookmark The Record / LSM coverage and the CSDD news page — ignore Telegram “full dump download” channels.
Phishing patterns to expect
Latvian-language SMS that open with your exact surname and plate are the high-danger tier. English-language WhatsApp forwards to diaspora relatives come next. Fake “Data Inspectorate compensation registration” pages will harvest more data than the original breach. Slow down when a message feels too accurate.
Canonical record and sources
Catalog: latvia-csdd2026 — 1,200,000 people (plus ~200,000 legal entities noted in writeup), companyConfirmed: true. Sources: The Record, LSM English, CSDD public notices summarized therein. BreachHistory will revise counts if CSDD publishes a tighter census.
Bottom line: a verified state vehicle-registry breach hitting most of Latvia’s population, with national IDs and plates in the mix, leadership resignations, and a fraud wave that writes itself. Treat every “CSDD” message as guilty until proven on the official domain.
For searchers landing on “Latvia data breach 2026” or “CSDD hack”: August 8–9 intrusion, August 18 scale disclosure, 1.2 million people, payment receipts since 2008, phones/emails not taken per agency, political crisis attached. That is the story — not a vague Eastern European dump with no named victim.
Businesses that used CSDD corporate accounts should inventory which employees’ personal codes might appear beside company registration numbers in the same receipt trails. Dual exposure (person + company) is how invoice-fraud crews prioritize targets.
Journalists should keep the LVM forestry ransomware and CSDD registry breach as separate incidents. Same country, same summer, different systems and data classes. Collapsing them into “Latvia got hacked again” erases the specific fraud advice people need.
International partners funding Baltic digital government projects should treat CSDD as a tabletop: internet-exposed legacy payment stores, incomplete monitoring handoffs between agency and contractor, and a population-scale notification problem when the census finally lands.
If you lived in Latvia in 2015, sold the car in 2019, and moved abroad in 2022, you can still be in the 2008–2026 receipt corpus. Time does not retire a national ID.
Finally, do not download alleged CSDD dumps “to check yourself.” That is how secondary malware and doxxing datasets spread. Use official guidance and bank monitoring instead.
Vehicle buyers and sellers mid-transaction should verify ownership documents through official channels more carefully for the next year. Forged paperwork that matches a real plate and historical address will look better than usual.
Insurers operating in Latvia should expect a spike in identity-linked claims disputes and social-engineering against claims adjusters who are read a correct personal code over the phone. Out-of-band verification beats trusting the caller’s trivia.
The honest one-sentence summary for residents: if CSDD ever took your money for a car or licence service, assume fraudsters may know enough to sound like the government — and only trust e.csdd.lv.
Why national ID + plate is a fraud multiplier
Latvia’s personal identity code is not a casual username. Paired with a license plate and a historical payment date, it lets a stranger pass the “do you know this customer?” test that call centers and courier desks still use. You do not need a stolen password to open a harmful conversation — you need trivia that used to live only inside CSDD receipt stores.
Plate numbers also bridge online and physical worlds. A scammer who knows your plate can invent a towing, insurance, or pollution-fine story that matches a car friends and neighbors recognize. That is harder to dismiss than a generic “your account is locked” email.
Incomplete addresses in some rows are cold comfort. Fraud crews concatenate other open sources — old white pages, leaked e-commerce dumps, social media — until the CSDD fragment becomes a full dossier. The breach is a seed, not the entire plant.
Timeline residents can keep straight
- August 8–9, 2026 — Intrusion weekend against CSDD systems holding historical payment receipts.
- August 13 — First public admission of a cyberattack; scale still unclear.
- August 14 — Public still told few quantitative details.
- August 18 — CSDD announces 1.2 million people and ~200,000 legal entities in scope; president demands leadership change.
- August 19–20 — Board resignations; interim governance; director signals departure after stabilization.
That multi-day gap between discovery and full population numbers is exactly when rumor channels invent larger or smaller counts. Stick to the August 18 agency figures until CSDD revises them.
What “payment receipts since 2008” really means
Two decades of fee history is a behavioral map: when you bought a car, when you renewed a document, which company fleet accounts paid on which dates. Criminals use that chronology to time lures — “your 2019 registration renewal was flagged in the cyber review; confirm within 24 hours.” The date is real; the urgency is fake.
Companies should assume AP clerks will see invoices that cite correct historical CSDD payment amounts. That accuracy is the tell of a compromised receipt archive, not proof the invoice is legitimate.
Contractor monitoring and shared responsibility
Public quarreling between CSDD and Tet about who should have seen the intrusion first is a governance story as much as a technical one. Citizens do not care which contract annex covered which firewall log. They care that an internet-exposed system with national IDs was reachable to a prepared attacker.
Other agencies reading this should inventory every “monitoring included” vendor clause and test whether alerts actually page humans when anomalous bulk reads hit legacy receipt databases. Paper SLAs do not stop August weekends.
If you are a foreign resident who briefly registered a car while on assignment in Riga, check whether your landlord or employer still has paperwork with your personal code. Secondary holders of copies sometimes become the weak phishing channel even when you left the country years ago.
Banks and fintechs serving Latvian customers should temporarily raise friction on government-fee payments initiated from new devices. A week of extra step-up authentication costs less than a wave of authorized-push-payment fraud dressed as CSDD settlements.
Teachers and municipal clerks who routinely handle citizen personal codes should get a one-page brief: after CSDD, more callers will recite correct codes. Reciting a code is not identity. Callback to a number on file is.
Tourists who rented cars through agencies that registered plates under local entities should ask those agencies whether traveler passport numbers were stored alongside CSDD payment trails. Secondary copies expand the blast radius beyond the agency’s own servers.
Civil-society groups can translate CERT.LV’s fraud warning into plain language posters for libraries and post offices — places where older residents still handle paper renewals. The people least online are often the most vulnerable to phone scripts that cite a real plate.
When CSDD eventually publishes more forensic detail — vulnerability class, exact table names, whether backups or live systems were hit — BreachHistory will fold that into the technical writeup without rewriting the population count unless the agency revises it.
Until then, the actionable public fact pattern is stable: verified agency confirmation, 1.2 million people, receipt fields since 2008, leadership crisis, fraud risk centered on personalized government impersonation. Act on that pattern; ignore dump-download folklore.
Insurance brokers selling motor policies in Latvia should train staff not to accept “CSDD verification codes” dictated by inbound callers. Outbound verification to the number on the policy file only. The breach makes confident-sounding callers cheaper to script.
Open-data advocates sometimes argue vehicle registries should be more transparent. This incident is a reminder that transparency about plate-to-model lookups is not the same as exporting twenty years of personal codes and payment amounts. Different tables, different duties of care.
Search coda: Latvia CSDD data breach August 2026, 1.2 million people, vehicle plates and national IDs, payment receipts since 2008, phones and emails not taken per CSDD, board resignations, CERT.LV fraud warning, canonical BreachHistory record linked above.
One last habit: if a message cites your plate correctly, that is a reason to slow down — not a reason to trust. Accuracy is what the CSDD theft sold to fraudsters. When in doubt, open e.csdd.lv yourself — never from a text. That single habit blocks most of the post-breach playbook.