Latvia’s Road Traffic Safety Directorate and Tet: Search for accountability begins after massive data breach in Latvia – CSDD chief points to Tet

Latvia’s Road Traffic Safety Directorate and Tet: Search for accountability begins after massive data breach in Latvia – CSDD chief points to Tet

Latvia’s Road Traffic Safety Directorate Suffers Major Cyberattack Amid Monitoring Failures

Latvia’s Road Traffic Safety Directorate (CSDD) was hit by a significant cyberattack between August 7 and 8, resulting in the theft of personal data belonging to 1.2 million individuals and records from 200,000 legal entities spanning 18 years of payment transactions. The breach was discovered and contained within hours by CSDD’s own cybersecurity team, not its contracted IT monitoring provider, Tet, which failed to detect the intrusion.

CSDD Chairman Aivars Aksenoks revealed that Tet, a telecommunications and technology firm under a five-year contract, was responsible for infrastructure maintenance, firewall protection, and incident monitoring services for which CSDD pays a substantial monthly fee. Despite this, Tet provided no alert during the attack. When CSDD later inquired, Tet confirmed it had not identified the breach.

The attack exploited a vulnerability in an internet-accessible CSDD system, according to CERT.LV, Latvia’s cybersecurity incident response team. While no customer phone numbers or email addresses were compromised, the scale of the data exposure has raised concerns about potential misuse.

Aksenoks also addressed claims that CSDD had rejected a monitoring agreement with CERT.LV, clarifying that no formal proposal had been submitted through proper administrative channels. Instead, a draft agreement was exchanged informally between a CERT.LV employee and a CSDD specialist who has since left the organization. CSDD has since forwarded the agreement to CERT.LV for signing.

Political and Operational Fallout
Latvian Prime Minister Andris Kulbergs (Progressive Party) held CSDD’s Management and Supervisory Boards accountable, instructing the Transport Minister Rihards Kozlovskis to assess whether officials should retain their positions. Kozlovskis has launched an accelerated internal investigation, with findings due in early September. The prime minister did not rule out the possibility of the attack being a hybrid operation by a foreign state targeting Latvia’s critical infrastructure.

Tet’s Role and Ownership
Tet, which provides CSDD’s IT infrastructure, is 51% state-owned through Public Asset Manager Possessor, with the remaining 49% held by Telia Company’s subsidiary, Tilts Communications. Telia is in the process of selling its stakes in Tet and Latvijas Mobilais Telefons (LMT) to Latvenergo, the Latvia State Radio and Television Centre (LVRTC), and a strategic investor, which could result in each party holding ~25% ownership in both companies.

In 2025, Tet Group reported €302.85 million in revenue (down 5.8% year-over-year) and a €20.59 million profit (up 14.2%). Tet itself saw €191.67 million in revenue (up 3.4%) and a 49.5% profit increase to €18.38 million.

CSDD, a state-owned joint-stock company under the Ministry of Transport, oversees vehicle registration, driver’s license issuance, roadworthiness inspections, and other critical services. The incident underscores vulnerabilities in Latvia’s cybersecurity oversight of public-sector infrastructure.

Source: https://bnn-news.com/search-for-accountability-begins-after-massive-data-breach-in-latvia-csdd-chief-points-to-tet-282962

Tet cybersecurity rating report: https://www.rankiteo.com/company/tet

Road Traffic Safety Directorate (CSDD) cybersecurity rating report: https://www.rankiteo.com/company/csdd

"id": "TETCSD1787121730",
"linkid": "tet, csdd",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1.2 million individuals and '
                                              '200,000 legal entities',
                        'industry': 'Transportation/Traffic Safety',
                        'location': 'Latvia',
                        'name': 'Road Traffic Safety Directorate (CSDD)',
                        'size': 'Large (state-owned)',
                        'type': 'Government Agency'}],
 'attack_vector': 'Exploited vulnerability in an internet-accessible system',
 'data_breach': {'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '1.4 million (1.2M individuals + '
                                              '200K legal entities)',
                 'personally_identifiable_information': 'Yes (excluding phone '
                                                        'numbers and email '
                                                        'addresses)',
                 'sensitivity_of_data': 'High (personal and financial data)',
                 'type_of_data_compromised': ['Personal data',
                                              'Payment transaction records']},
 'date_detected': '2024-08-07',
 'date_resolved': '2024-08-08',
 'description': 'Latvia’s Road Traffic Safety Directorate (CSDD) was hit by a '
                'significant cyberattack between August 7 and 8, resulting in '
                'the theft of personal data belonging to 1.2 million '
                'individuals and records from 200,000 legal entities spanning '
                '18 years of payment transactions. The breach was discovered '
                'and contained within hours by CSDD’s own cybersecurity team, '
                'not its contracted IT monitoring provider, Tet, which failed '
                'to detect the intrusion.',
 'impact': {'brand_reputation_impact': 'Significant reputational damage to '
                                       'CSDD and Tet',
            'data_compromised': 'Personal data of 1.2 million individuals and '
                                'records from 200,000 legal entities',
            'identity_theft_risk': 'High',
            'operational_impact': 'Disruption of CSDD services, internal '
                                  'investigation launched',
            'payment_information_risk': 'High',
            'systems_affected': 'CSDD payment transaction systems'},
 'initial_access_broker': {'entry_point': 'Internet-accessible CSDD system'},
 'investigation_status': 'Ongoing (accelerated internal investigation by '
                         'Transport Minister)',
 'lessons_learned': 'Failure of third-party monitoring provider (Tet) to '
                    'detect the breach; need for improved cybersecurity '
                    'oversight in public-sector infrastructure',
 'motivation': ['Data Theft', 'Potential hybrid operation by a foreign state'],
 'post_incident_analysis': {'corrective_actions': ['Formalizing agreement with '
                                                   'CERT.LV',
                                                   'Internal investigation '
                                                   'into Tet’s performance'],
                            'root_causes': ['Vulnerability in CSDD system',
                                            'Failure of Tet to detect the '
                                            'breach']},
 'recommendations': ['Strengthen monitoring agreements with cybersecurity '
                     'agencies like CERT.LV',
                     'Enhance internal cybersecurity capabilities',
                     'Review third-party vendor contracts for accountability'],
 'references': [{'source': 'CERT.LV'},
                {'source': 'CSDD Chairman Aivars Aksenoks'},
                {'source': 'Latvian Prime Minister Andris Kulbergs'}],
 'response': {'communication_strategy': 'Public disclosure by CSDD Chairman '
                                        'and Prime Minister',
              'containment_measures': 'Breach contained within hours by CSDD’s '
                                      'cybersecurity team',
              'incident_response_plan_activated': 'Yes',
              'third_party_assistance': 'CERT.LV (Latvia’s cybersecurity '
                                        'incident response team)'},
 'stakeholder_advisories': 'Prime Minister holds CSDD Management and '
                           'Supervisory Boards accountable; potential foreign '
                           'state involvement suspected',
 'title': 'Latvia’s Road Traffic Safety Directorate Suffers Major Cyberattack '
          'Amid Monitoring Failures',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Unknown vulnerability in CSDD system'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.