Latvia CSDD
1.2 million people in a country of 1.8 million. Payment receipts going back to 2008. The entire management resigned six days after disclosure.
What happened?
Latvia's Road Traffic Safety Directorate was attacked over the weekend of August 8 and 9, 2026. The breach affected records belonging to more than 1.2 million people and 200,000 businesses and other legal entities. Latvia's population is just over 1.8 million.
The agency's supervisory board resigned on August 18, six days after the agency disclosed that attackers had taken payment records. A criminal investigation is open. Reporting indicates the agency's monitoring provider missed the intrusion and that disclosure to national authorities was delayed.
What data was actually inside?
Personal identification numbers and company registration numbers, vehicle licence plate numbers, payment amounts and dates, and the addresses listed on vehicle registration certificates. Attackers accessed payment receipts dating back to 2008.
The Latvian personal identification number is a national identifier used across banking, healthcare, and government services. Paired with a home address from a vehicle registration certificate, that is a complete civil identity record. It cannot be reissued in any practical sense.
Eighteen years of receipts, held not because anyone decided that retention period was appropriate, but because the system was built in 2008 and disposal was never a project.
Who gets hurt and how?
Roughly two-thirds of a country's population, which changes the nature of the problem. Individual remediation advice — monitor your accounts, change your passwords — assumes the affected group is a minority who can be told apart from everyone else. Here the breached population is the default population.
Because the personal identification number is used across banking, healthcare, and public services, and because it is paired with a verified residential address, the dataset supports identity fraud, account takeover, and highly credible impersonation of state services. Latvian institutions cannot treat knowledge of an identification number as evidence of identity any more, and that has consequences for every verification workflow in the country.
Vehicle registration data adds a physical dimension: which person, at which address, owns which specific vehicle.
What did they think they were doing right?
The agency had engaged a monitoring provider, which is the standard answer for an organisation without a full internal security operations capability, and a reasonable one. Detection was outsourced to specialists.
Reporting indicates the provider missed the intrusion. That failure is worth stating carefully: outsourcing detection transfers the work, not the accountability, and it introduces a dependency that is invisible until it fails. The agency's confidence in its own posture was, in effect, confidence in a supplier's alerting configuration.
What did they not know about their own data?
The 2008 receipts are the clearest signal in the incident. No one decided to keep eighteen years of payment records containing national identifiers alongside home addresses. The data accumulated because the system supported it and nothing ever forced a review.
GDPR's storage limitation principle requires personal data to be kept no longer than necessary for the purpose. An agency that could describe its own holdings would have found this during any serious retention review — the receipts serve no operational purpose eighteen years on, and disposing of them would have reduced the affected population dramatically at no cost to the mission.
Note also where the resignations came from. Not the intrusion itself, which no board can prevent personally, but the delay in disclosure and what that delay revealed about how little the agency could say about its own systems.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
GDPR requires notification to the supervisory authority within 72 hours of awareness, and communication to affected individuals without undue delay where high risk is likely. With national identifiers and home addresses exposed for two-thirds of the population, the high-risk threshold is not arguable. Delayed disclosure to national authorities is itself a compliance question separate from the breach.
Beyond data protection law, Latvian leadership has raised whether the intrusion constitutes a threat to critical state infrastructure, which moves the matter into national security channels alongside the criminal investigation. Individual notification at this scale is close to meaningless as a protective measure — when nearly everyone is affected, a letter tells the recipient nothing they could not assume.
What would have changed the outcome?
A retention review that could only have happened with an inventory — because disposing of receipts nobody needed would have shrunk the breach by years of records.
The intrusion was not preventable by any single control, and the board that resigned did not cause it. What was available in advance was the choice not to hold eighteen years of national identifiers and home addresses in a live payments archive. That choice requires knowing the archive exists, what is in it, and how far back it goes. Data you cannot describe is data you cannot dispose of, and every year you keep it enlarges the worst day you will eventually have. See also our analysis of the Sogang University breach, where the affected population was fifteen times the current campus.
Latvia’s CSDD found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.