CSDD data breach in Latvia: how to dodge the fake fines coming next

18.08.2026 5 min 2

Over the weekend Latvia's Road Traffic Safety Directorate (CSDD, the agency that registers cars and issues licences) was breached. On 18 August the scale became clear: attackers pulled the history of payment receipts, the personal data of about 1.2 million people and around 200,000 companies over 18 years. Logins and passwords were untouched, so there is no account action to take. But because of what was stolen, a wave of fake CSDD messages is coming, and it is worth preparing now.

1.2Mpeople in the leaked data
200kcompanies affected
18 yearsof receipts in the archive

What leaked and why it is dangerous

The receipts held a personal identity code or registration number, a name or company name, the amount and date of the payment, the vehicle plate and an address. Phone numbers and email were not affected, and the address is sometimes incomplete. It looks like a dull payment archive, but for a scammer it is a ready script: they know your name, your identity code, your car by its plate and that you really paid CSDD. A message that greets you by name and quotes your plate beats ordinary spam.

CERT.LV gave a separate warning about the identity code. In Latvia it identifies you across many systems, so criminals may try to log in somewhere under your code and a confirmation request lands on your phone. If you did not start it, do not approve it.

The messages and calls to expect

The scams will circle your car and your money, because that is what they know. Likely versions:

  • A fake fine. "You have an unpaid fine, pay via the link before this date or face penalties."
  • Vehicle re-registration. "Your car is being transferred to someone else. If this is not you, cancel urgently via the link." Fear of losing the car makes you rush.
  • Annual vehicle tax. "Your yearly tax is due, pay online via the link with a discount today."
  • Roadworthiness test or licence renewal. "Your inspection is expiring, book and pay via the link."
  • A refund. "CSDD is returning your overpayment, enter your card details to receive it." Refunds never work this way.
  • A call from "CSDD". They quote your real data for trust, then ask for a code from an SMS or a click on a link.

How to protect yourself, step by step

  1. Check any message about a fine, tax, re-registration or refund yourself on e.csdd.lv or in the CSDD app. Not through a link, but by typing the address or opening the app. CSDD advises the same.
  2. Do not open links in emails or texts "from CSDD" and do not enter card details or codes on them. A real fine or tax shows up in your account; you never need a link for it.
  3. Do not approve a login or a signature if the request arrives while you started nothing. This covers Smart-ID, eParaksts and bank push: approving on someone else's request lets a stranger in.
  4. Do not read out codes from SMS or push, even if the caller knows your name, code and plate. Many people hold that data now, and it does not prove who is calling.
  5. In doubt, hang up and call CSDD yourself on the number from csdd.lv. Never call back the number in a suspicious message.
  6. Turn on notifications for logins and payments in your account and your bank. Then you see a real charge first, not from someone else's email.

One simple rule. No agency makes you pay a fine or tax through a link in an email. If a message about money arrives, do not follow the link; log in to your account on the official portal and check whether the charge is there. If it is not, the message is fake.

What has been done, and what it does not undo

The CSDD IT team and CERT.LV stopped the attack, and police are investigating. Early information says the attack was planned and the weak point was a system reachable from the internet; whether the rules for such systems were met, including penetration tests and multi-factor authentication, is being checked. There is no sign yet that the data has been used. But it stays with the attackers for good, so caution should become a habit, not a week: your identity code, name and plate do not change, and fake messages built on them can arrive months from now.

Do I need to change my e.csdd.lv password?
Logins and passwords were not in this leak, so there is no rush. But if you have not changed it in a long time or reuse it elsewhere, changing it and turning on two-factor is worth it anyway.
I already got a fine from CSDD. Is it a scam?
Not necessarily, but do not check it through the link. Go to e.csdd.lv or the app and see whether the fine is in your account. If not, the message is fake.
Would a VPN help here?
No. The data was taken from CSDD servers, not your connection, and the fake messages reach you directly. Only attention and checking on the official portal help.
What if I already entered my card details?
Call your bank at once and block the card, then watch for charges. If you entered a password for e.csdd.lv or your bank, change it from another device and turn on two-factor.

data breachphishinglatviaprivacycybersecurity

Read also