Latvia’s whole agency board resigned while Slovakia defended publishing birth numbers

Latvia’s whole agency board resigned while Slovakia defended publishing birth numbers

Within four days a Baltic state confirmed it had lost payment records covering two-thirds of its population and its entire leadership walked out, while a neighbouring EU government put birth numbers, home addresses and handwritten signature specimens online and called it lawful. The technical causes differ. The file that reaches a fraudster does not.

Latvia’s Road Traffic Safety Directorate, CSDD, confirmed on 18 August that an attacker had taken data from payment receipts covering 1.2 million people and roughly 200,000 companies and other legal entities. Latvia has just over 1.8 million residents. The receipts run back to 2008, so the loss is eighteen years of transactions with the body that registers every vehicle and issues every driving licence in the country. By Wednesday afternoon the supervisory board had quit, the transport minister had told the management board it could not carry on, and the management board said it would leave on 20 August.

On the same Wednesday in Bratislava, Slovakia’s data protection authority opened proceedings against the Ministry of Justice. The new commercial register portal, live since 17 August, serves scanned company deeds containing birth numbers, full residential addresses, identity document numbers and handwritten signature specimens to anyone who retypes a four-digit code. No login, no chip card, no stated reason.

One country was robbed. The other published. The artefact that reaches a criminal is close to identical, and in both cases its most durable element is the national identification number that citizens carry for life and that state e-services also accept as a user name.

Eighteen years of receipts, taken over three days

The attack began during the night of 7 to 8 August. CSDD and the national incident response body CERT.LV state that the attacker retrieved receipt data between 8 and 10 August inclusive. The exposed categories are narrow but unusually well matched to impersonation: personal identity code or company registration number, name or company name, payment amount, payment date, vehicle registration plate, and the address recorded on the day the service was provided. Customer telephone numbers and e-mail addresses were not touched, address data is incomplete in some records, and user names and passwords were not compromised.

The disclosure sequence matters as much as the volume. CSDD first described a complex attack on 13 August. On 14 August officials still could not say how large the breach was. The full figure arrived on 18 August, ten days after the intrusion. CERT.LV told Latvian public broadcaster LSM that the attackers exploited a vulnerability in a CSDD system exposed to the internet, that several mandatory cybersecurity requirements had not been met, and that notification of the incident reached it late.

That last point has a precise legal frame. Latvia’s National Cybersecurity Law, in force since 1 September 2024, requires an early warning to the competent incident response body within 24 hours of a notable incident and an initial report within 72 hours, with minimum security requirements set by Cabinet Regulation No 397. CSDD says it has informed the State Data Inspectorate and preserved its material for assessment. State police have opened criminal proceedings, and the agency reported blocking a second targeted attack the following weekend.

This is not an isolated event in the Latvian state sector. In June the state forestry company suffered a ransomware attack that disrupted its mapping platform and its systems for exchanging information with contractors, drawing extra attention because the same company had worked on the electronic voter registration system. Officials said the election system was unaffected because it was developed separately. Two serious incidents at state-owned companies within ten weeks is a pattern worth naming, particularly in a country that has spent three years describing itself as a front-line target for hybrid operations. Officials have not ruled out a foreign origin for the CSDD attack, and CERT.LV has said the methods indicate preparation and technical competence.

A four-digit code where a chip card used to be

Slovakia’s situation began with a law rather than an intruder. Act No 29/2026 on the commercial register took effect on 17 August, presented by the Ministry of Justice as a step towards wider digitisation and faster access, with electronically supplied information carrying legal effect. The register and its collection of deeds have been public for decades; the European e-Justice Portal records that both are available to everybody, and the collection has been kept electronically since October 2020.

What changed is friction. The technology news site Živé.sk reported, and broadcasters including ta3 and JOJ verified on randomly chosen companies, that documents which previously required a request, electronic identity card authentication and delivery to a state electronic mailbox can now be opened by retyping a code the portal itself displays. One verified document, a 2023 certificate authenticating a signature, carried a named individual’s date of birth, complete birth number, exact residential address and identity card number, none of it redacted.

A check designed to distinguish a human from a script now stands where identity verification used to stand. Journalists withheld the search method and the company names. The Personal Data Protection Office examined the portal on the evening of 18 August and opened proceedings against the Ministry of Justice the next day, stating that the commercial register law excludes birth numbers from publication and that documents must be anonymised before release. Justice Minister Boris Susko rejected the criticism, said the same data had always been reachable, pointed to Czech practice, and told reporters the law would not change.

The identifier is the payload

Neither incident is dangerous because of any single field. Both are dangerous because of one field’s dual role. CERT.LV set this out plainly for Latvia: the personal identity code is used as the user number for logging into Smart-ID and eParaksts mobile, and through them into services including Latvija.gov.lv, e-CSDD, the health portal and the tax system. The code alone opens nothing. It is enough, though, for a fraudster to trigger an authentication request that the citizen then approves on their own phone.

The remedy CERT.LV recommends shows how deep the design problem runs. Users are advised to check whether their eParaksts user number is their personal identity code and, if so, replace it with seven randomly generated digits. A three-digit security code shown in the app and typed into the browser guards against the same trick. The instruction that matters is simpler: an authentication prompt you did not start should never be approved.

Slovakia’s exposure is the same logic in a different order. The birth number is a lifelong identifier that many institutions still treat as a semi-secret confirmation of identity, and the register serves it alongside a date of birth, an exact address, a document number and an image of the person’s handwriting. Živé.sk made the point that a name or address alone rarely supports a convincing attack, while the assembled set does. Banks and other institutions apply further verification, so possession of the file does not open an account by itself. It does raise the quality of every subsequent attempt.

Nine million euros of monitoring that did not raise the alarm

The Latvian argument has already moved to the contract. CSDD board chair Aivars Aksenoks said the telecommunications company Tet, which supplies part of the agency’s IT infrastructure and monitoring, did not detect the intrusion; CSDD staff found it themselves and stopped it within hours. Tet chairman Uldis Tatarcuks responded that investigators must first establish how and when access was obtained and where controls failed, and noted the company is responsible for defined parts of the estate rather than the whole network.

Public procurement records reported by LSM give the arrangement a price. The February 2022 contract for IT infrastructure provision and management for the vehicle and driver register was worth €8.989 million excluding VAT, raised to €9.043 million in spring 2025. Tet won on the economically most advantageous offer, scoring 85 points out of 100, including the maximum 40 for price and 45 of 60 for risk assessment. Two subcontractors are attached to the contract.

The scoring itself is worth reading. Price carried 40 points and risk assessment 60, of which the winning bid took 45. On paper that weighting looks prudent, since security counted for more than cost. In practice a risk score awarded at tender describes a document, not a running defence, and nothing in a procurement file guarantees that the perimeter drawn in 2022 still matched the systems exposed to the internet in 2026. Four years is long enough for an agency to add applications that nobody remembered to place inside the monitored estate.

Transport Minister Rihards Kozlovskis has ordered an accelerated internal investigation covering the circumstances, the responsible persons and the Tet contract itself, including whether the services purchased matched the risks. This is the part with transferable value. A monitoring contract describes an obligation to watch specified components; it does not by itself allocate responsibility for an internet-facing application that was outside the agreed perimeter. Boards that cannot say precisely which assets their supplier watches are buying reassurance rather than detection.

Theft and disclosure converge on one document

The two cases invite an obvious objection: a crime and a statute are not comparable. Legally that is right, and it matters for liability, insurance and prosecution. From the position of the person whose data is in circulation, the distinction is thinner than it looks.

Consider what a fraudster needs to run a convincing approach. First, a plausible pretext, which both datasets supply: an unpaid vehicle fee in Latvia, a company filing problem in Slovakia. Second, details that a stranger should not know, which prove the caller is who they claim to be. Third, a channel to a decision, usually an approval tapped on a phone or a payment made in the following ten minutes. The Latvian receipt file supplies the pretext and the proof in one record; the Slovak deed supplies the proof and a handwriting sample as well. Neither delivers the third step by itself, which is why both governments correctly say that accounts are not directly at risk. That reassurance addresses the weakest part of the attack chain.

There is also a difference in how each exposure ages. Stolen data is a fixed set that degrades slowly as people move house or change vehicles. Published data refreshes: every new deed filed into the collection adds current records, so the Slovak set stays accurate for as long as the practice continues. A breach is an event with an end date. A publication rule is a process without one.

The two incidents side by side

DimensionLatvia, CSDDSlovakia, commercial register
TriggerIntrusion via an internet-facing systemPortal launched under Act No 29/2026
DatesData taken 8–10 August, scale confirmed 18 AugustLaw effective 17 August, findings published 19 August
Core identifier exposedPersonal identity codeBirth number
Supporting fieldsName, plate, address, payment amount and dateDate of birth, address, document number, signature specimen
Population reached1.2 million people, 200,000 legal entitiesPersons named in company deeds
Supervisor’s stepNotification to the State Data Inspectorate, police caseProceedings opened against the Ministry of Justice

The table isolates the asymmetry worth arguing about. Latvia’s exposure is bounded by what one attacker retrieved during three days, and the agency can tell an individual which categories were affected. Slovakia’s is bounded only by how many scanned deeds contain unredacted fields, a number nobody has published.

Resignations in Riga, a defence of the law in Bratislava

Latvian accountability moved in roughly 48 hours. President Edgars Rinkēvičs said on 18 August that the leak threatened national security and that the agency’s management could not continue in office. Prime Minister Andris Kulbergs called for both boards to go. On Wednesday morning the supervisory board, chaired by Kristiāns Godiņš, submitted its resignation before a meeting with the minister, arguing that an independent external and internal security audit could no longer be run properly in the current climate. Kozlovskis then told the management board he saw no basis for it to continue, and by the afternoon Aksenoks confirmed the board would step down on 20 August.

Slovakia produced the opposite reflex. Susko’s position is that entrepreneurs must accept a degree of interference with their rights, including their personal data, in order to protect third parties. The ministry’s written statement goes further and is the stronger version of the argument: the register publishes because the law obliges it to, it cannot decide for itself which parts of a filed document to withhold, the new rules expressly address documents containing data that would not otherwise be published separately, and the data protection authority raised no objection during the legislative process.

Opposition parties split along a useful line. KDH called for expert discussion and warned that transparency must not endanger ordinary people. SaS accepted publication in principle and blamed execution, arguing the state could have kept the deeds public while adding verification, and pointed to Estonia. The dividing question is not whether the register should be open. It is whether openness of documents requires openness of every field inside them.

The proportionality argument has a boundary

The Slovak ministry is standing on real ground, and the strongest support for its position comes from the Court of Justice of the European Union. In Case C-398/15, Manni, decided in March 2017, the Court held there is no right to be forgotten in the companies register, because public registers exist to give third parties legal certainty about entities whose only guarantee is their assets. Restricted access is possible only exceptionally, long after dissolution, on a case-by-case basis.

The same judgment contains the boundary. The Court found the interference with private life proportionate in part because only a limited number of personal data items are entered in the register. That reasoning covers a defined set of identifying entries. It does not obviously extend to bulk publication of scanned notarial certificates carrying a birth number, an identity document number and a specimen of a person’s handwriting. Slovakia’s supervisor makes the narrower version of the point: the scope of published data must match what the purpose requires, and the birth number at minimum falls outside it.

The ministry’s second defence, that the supervisor did not object while the law was being drafted, carries less than it appears. Consultation on a legislative text addresses what the statute permits, not how an implementation renders scanned attachments. A drafting body reading a clause on the publication of filed documents would not necessarily anticipate that decades of notarial certificates would be served in full through a portal with a captcha in front of it. The complaint is about the second thing, and the ministry has not yet said whether redaction was considered and rejected, or simply not built.

Several things remain unestablished, and they matter. No public evidence yet shows the Latvian data being used in fraud, though CERT.LV expects social engineering campaigns. Nobody has quantified how many Slovak documents or people are affected. The Latvian cybersecurity law allows fines up to €10 million or 2% of turnover for essential service providers while exempting state and municipal institutions, and the available sources do not establish how the supervisor will classify a state-owned joint-stock company such as CSDD. Attribution is also open: officials have not ruled out a foreign hybrid operation, and no evidence has been published either way.

Decisions worth making before the phone rings

For people in Latvia, the concrete steps are short. Check the eParaksts user number and change it if it is your identity code. Refuse any authentication request you did not start. Verify anything claiming to come from CSDD by opening the official app or site yourself rather than following a link. Anyone may ask CSDD which categories of their data were affected, and may complain to the State Data Inspectorate.

For Slovak directors and shareholders, review your own company’s deeds first, since checking your own file spreads nothing. Where an unredacted document appears, raise it with the operator before escalating; the supervisor’s own guidance is to exercise rights with the controller first, and a complaint to the Personal Data Protection Office costs nothing.

Around 200,000 Latvian companies appear in the stolen receipts, and their exposure differs from an individual’s. A registration number, a plate and a past payment to CSDD are exactly the ingredients of an invoice fraud aimed at a finance clerk, particularly for fleets where vehicle paperwork is routine and rarely questioned. Firms with company vehicles should tell whoever pays invoices that a message quoting a real plate and a real past payment is not evidence of anything, and should require a second channel for any change of bank details.

The wider obligation sits with everyone who verifies identity for a living. Knowledge of a birth number, a date of birth, an address or a plate is now evidence of nothing. Banks, insurers, telecoms operators, notaries and public offices that still treat these as confirming details should assume an adversary holds them, and should treat a matching handwritten signature with the same suspicion, because specimens are now in circulation. For boards, the Latvian sequence is the lesson: know which assets your monitoring supplier actually watches, and rehearse the 24-hour and 72-hour reporting clocks before you need them.

The identifier problem outlives both governments

Both stories will be read as failures of competence, and both partly are. The more durable finding is structural. Latvia and Slovakia each built digital government on a single lifelong number that functions simultaneously as a database key, a proof of identity and, in Latvia’s case, a login handle. Any system with that property converts every leak into a permanent liability, because the compromised element cannot be reissued the way a card or a password can. When Slovak opposition politicians reached for Estonia as the model to copy, they were pointing at a state that treats verified access as a separate layer from the identifier itself, and they were arguing about implementation rather than proposing to close the register.

Two developments would show the lesson has landed. In Slovakia, the test is whether the ministry anonymises the fields the supervisor named, and whether it does so before the proceedings force it. Susko’s refusal to change the law is not the same as refusing to redact a scan, and the ministry has room to do the second while defending the first. In Latvia, the test is whether the accelerated investigation produces enforcement under the cybersecurity law rather than resignations alone, given that CERT.LV has already stated mandatory requirements went unmet.

If the outcome is three departed board members and a portal that keeps serving birth numbers, then the cost of both incidents has been paid entirely by citizens who had no say in either decision. The evidence available on 19 August supports a narrower judgment than the political noise suggests. Latvia was breached because an internet-facing system was left vulnerable and monitoring did not catch it. Slovakia exposed data because nobody built redaction into a publication duty. Only the second failure was avoidable at zero cost to the stated policy goal, which is why it is the one that should be corrected first.

Practical answers on the CSDD breach and the Slovak register

Was my data taken in the CSDD attack?

If you paid CSDD for any service since 2008, treat it as likely. CSDD says every person has the right to ask whether their data was affected and which categories were involved, using the request procedure set out in the privacy policy on its website.

Which fields did the attacker actually get?

Personal identity code or company registration number, name or company name, payment amount, payment date, vehicle registration plate, and the address registered on the day the service was received. Telephone numbers, e-mail addresses, user names and passwords were not affected.

Can someone log into my accounts with a stolen personal identity code?

Not on its own. The code works as a user number for Smart-ID and eParaksts mobile, so a fraudster can trigger an authentication request, but only you can approve it on your device. Never confirm a prompt you did not initiate.

Should I change my eParaksts user number?

CERT.LV advises checking it and, if it is your personal identity code, replacing it with a combination of seven randomly generated digits. This is done at eParaksts.lv after logging in with eParaksts mobile or an eID card.

Who resigned at CSDD and when?

The supervisory board submitted its resignation on the morning of 19 August. The management board, chaired by Aivars Aksenoks, announced the same day that it would leave its posts on 20 August, after the transport minister said he saw no basis for it to continue.

Is the Slovak register leak a hack?

No. The documents are published by the state under the commercial register law. The dispute concerns whether unredacted fields inside those documents should be publicly served, and how easily anyone can reach them without identity verification.

What did the Slovak data protection authority actually do?

It examined publicly available documents on 18 August and opened proceedings against the Ministry of Justice on 19 August, on its own initiative. It will examine how birth numbers reached the public and whether the ministry met its obligations under the GDPR and the national data protection act.

Which documents contain the sensitive fields?

Scanned items in the collection of deeds, particularly older notarial certificates authenticating signatures. Basic register entries for directors and shareholders show far less. The number of affected documents has not been published.

What can I do if my birth number appears in a company document?

Raise it with the controller first, which means the register operator or the Ministry of Justice. If you believe your data is processed unlawfully, you can file a free complaint with the Personal Data Protection Office and attach evidence. The office assesses lawfulness case by case.

Does either incident mean my bank account is at risk?

Not directly. Banks use additional verification beyond identity numbers and addresses. The realistic risk is targeted fraud: calls, messages and e-mails that quote accurate personal details to earn trust before asking for a code, a confirmation or a payment.

Author:
Jan Bielik
CEO & Founder of Webiano Digital & Marketing Agency

Latvia's whole agency board resigned while Slovakia defended publishing birth numbers
Latvia’s whole agency board resigned while Slovakia defended publishing birth numbers

This article is an original analysis supported by the sources cited below

Noslēgusies CSDD kiberincidentā izgūto datu analīze
CSDD’s own 18 August statement establishing the 1.2 million and 200,000 figures, the 8–10 August exfiltration window, the receipt data reaching back to 2008 and the exact list of affected data categories.

CSDD saskāries ar kiberdrošības incidentu
CERT.LV’s incident warning, including Varis Teivāns on social engineering risk and the advice for eParaksts mobile users to replace an identity-code user number with seven random digits.

Data of 1.2 million people breached in recent CSDD cyberattack
Latvian public media’s English account of the disclosure timeline from 13 to 18 August and President Rinkēvičs’s statement that the leak threatened national security.

Visa CSDD vadība atkāpjas no amata
Source for the resignations of both boards, the named members, Kozlovskis’s accelerated internal investigation and the procurement figures for the CSDD contract with Tet.

Latvian officials resign after cyberattack exposes data on 1.2 million people
English-language reporting on the dispute between CSDD and Tet, including Aksenoks’s claim that Tet did not detect the intrusion and Tatarcuks’s response.

Nacionālās kiberdrošības likums
The Latvian statute in force since 1 September 2024 setting the 24-hour early warning and 72-hour initial report duties, the minimum requirements regulation and the penalty ceilings and exemptions.

Úrad: Citlivé údaje v obchodnom registri mali byť anonymizované
TASR’s report of the data protection office opening proceedings on 19 August, its finding that documents should have been anonymised, and its position that the birth number falls outside necessary publication.

Ministerstvo reaguje na zverejnenie údajov v obchodnom registri
The Ministry of Justice’s written defence: publication is a statutory duty, the register cannot decide which parts of a document to withhold, and the supervisor raised no objection during drafting.

Opozícia kritizuje uľahčenie prístupu k údajom cez obchodný register
Opposition responses from KDH, SaS and Slovensko, plus Susko’s statement that entrepreneurs must tolerate some interference with their data rights.

Štát sprístupnil viac, než mal
Broadcast confirmation of the Živé.sk findings, the four-digit code replacing chip-card identification, and the argument that the combination of fields carries the risk.

Business registers in EU countries: Slovakia
The European e-Justice Portal’s description of the Slovak commercial register and collection of deeds as available to everybody, administered by the Ministry of Justice and kept electronically since October 2020.

Judgment in Case C-398/15 Manni
The Court of Justice press release establishing that no right to erasure applies in companies registers, and that the Court’s proportionality finding rested partly on the limited number of data items entered.

Citing this article? Brief excerpts are welcome. Please credit Webiano.digital, name the author where stated, and include a link to https://webiano.digital and to this original article. Full or substantial republication requires prior written permission. Read our Copyright and Content Use Policy.

This article was prepared with the assistance of artificial intelligence tools. The content underwent expert human review, and Webiano Digital & Marketing Agency assumes editorial responsibility for its final version and publication.