DistantNews
Support us
Stolen CSDD data could be used for years, expert warns
๐Ÿ‡ฑ๐Ÿ‡ป Latvia /Crime & Justice

Stolen CSDD data could be used for years, expert warns

From Delfi Latvia · () Latvian

Translated from Latvian, summarized and contextualized by DistantNews.

At a glance

News Sources not specified Context piece
  • A cybersecurity expert warns that data stolen from Latvia's Road Traffic Safety Directorate (CSDD) could be used for years, potentially by Russian scammers.
  • The expert noted that vulnerabilities in CSDD systems, some of which were known and fixed, may have been exploited by hackers.
  • Stolen data can be sold on the black market and used by fraudsters to create highly convincing phishing scams, impersonating official institutions.

Data stolen in a cyberattack on Latvia's Road Traffic Safety Directorate (CSDD) could be exploited for years, with a cybersecurity expert warning that Russian scammers are a likely recipient.

I when I saw those vulnerabilities on the CSDD page, I just wanted to cry.

โ€” Elviss Strazdiล†ลกThe cybersecurity expert expressed dismay over the state of CSDD's online vulnerabilities.

Elviss Strazdiล†ลก, a cybersecurity expert, stated that the primary concern is not the attacker but where the compromised data will end up. He suggested that a "non-friendly" state could be behind the attack, or that hackers might have exploited previously unknown vulnerabilities despite some known issues being addressed.

The reality is that hackers look for vulnerabilities on the internet, including with the help of artificial intelligence.

โ€” Elviss Strazdiล†ลกStrazdiล†ลก described the general landscape of cyber threats.

Strazdiล†ลก explained that hackers often target "abandoned" or "forgotten" systems that institutions believe are no longer in use. However, these are precisely the systems hackers frequently exploit. He added that even if the attacker wasn't a hostile state, the data could still be acquired on the black market.

The most important thing is not the attacker, but where the data ends up.

โ€” Elviss Strazdiล†ลกStrazdiล†ลก emphasized the long-term implications of the data breach.

Fraudsters can use this data to create highly convincing phishing scams. By including specific details like a car's registration number, they can trick individuals into believing messages about traffic violations are legitimate, especially when the sender ID is spoofed to appear as CSDD. The only giveaway might be a link leading to a fake website instead of the official CSDD domain.

There is no better way to convince a person than by showing them real data, because, in the victim's opinion, only a specialist could know such information.

โ€” Elviss Strazdiล†ลกStrazdiล†ลก explained how stolen data enhances the credibility of phishing scams.
DistantNews Editorial

Originally published by Delfi Latvia in Latvian. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.