Latvia Orders Review into Massive CSDD Data Leak; Chairman Won't Resign
Translated from Latvian, summarized and contextualized by DistantNews.
At a glance
- Latvia's Transport Minister has ordered an expedited internal review into a massive data leak at the Road Traffic Safety Directorate (CSDD).
- The investigation will assess the responsibility of CSDD board and council members and the reasons behind the data breach, which affected 1.2 million individuals and 200,000 legal entities.
- CSDD Chairman Aivars Aksenoks stated he does not plan to resign, asserting no violations from the board's side, while the Prime Minister suggested the attack could be foreign hybrid warfare.
Latvia's Transport Minister has initiated an urgent internal investigation into a significant data leak at the Road Traffic Safety Directorate (CSDD), following the exposure of personal data belonging to 1.2 million individuals and 200,000 legal entities. The review, expected to be completed by early September, will scrutinize the accountability of CSDD's board and council members and the circumstances that allowed such a large-scale breach.
The aircraft remain available for deployment in problem cases, during disasters, and so on, within the province.
The ministry is collaborating with the State Police and other security agencies to uncover the root causes of the data compromise. The investigation will also evaluate the cyber incident's impact on the directorate's operations, information systems, and service continuity. Furthermore, it will examine the actions of CSDD officials and employees in preventing, detecting, and managing the cyberattack, including adherence to internal procedures.
Despite the breach, CSDD Chairman Aivars Aksenoks has stated he has no intention of resigning, claiming the board has committed no wrongdoing. He noted that the CSDD council has commissioned an emergency audit, and an internal security committee is conducting a thorough review of the cyberattack.
There is actually no difference in terms of rationality.
Earlier reports indicated that the attack exploited a vulnerability in a publicly accessible CSDD system. The breach involved data from payments made to the directorate over the past 18 years. The Prime Minister has called for the CSDD board and council to assume full responsibility, tasking the transport minister with evaluating the suitability of officials for their positions. He also raised the possibility that the attack could be a hybrid warfare tactic orchestrated by a foreign entity targeting Latvia's critical infrastructure.
The company leader also confirmed today that there are no problems anywhere.
Originally published by Delfi Latvia in Latvian. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.