Latvia arrests a hacker who took device unlock codes from a repair chain's database

23.09.2026 10 min 26

On 23 September Latvia's State Police said they had detained a 23-year-old man in Riga on suspicion of breaking into the websites of at least two Latvian companies and demanding money to stay quiet. One of the victims is TSC, the repair arm of the LMT telecoms group, which fixes phones, smart devices and household appliances in Latvia, Lithuania and Estonia.

The leak itself surfaced on 11 September. TSC said roughly 7% of its customers were affected, and the names and phone numbers are the least of it. For some people the repair database also held the unlock passcode of the device they handed in, its IMEI, a bank account number and the entrance code of their building.

In short

  • The suspect, born in 2003, was detained on 15 September; police made it public on 23 September.
  • He got into the database behind the repair request form on tsc.lv. About 7% of customers were affected.
  • Beyond names and contacts, some records held device passcodes, IMEI numbers, bank accounts, delivery addresses and building door codes.
  • Police say the data was not passed on to anyone else. The man faces up to five years.

What actually leaked

According to TSC's own statement, the attacker used a vulnerability on the company website and reached the database that stores repair requests. For most customers the stolen set is dull and familiar: first and last name or company name, phone number, email address, repair receipt number. In part of the records it goes much further, because the repair form asks for it: the IMEI of the device, the passcode that unlocks the device handed in for repair, bank account numbers and personal identity codes used for settlements, delivery addresses, and the entrance door code of the building where a courier was supposed to collect the item.

The leak covers customers whose requests went through the website: people who booked a repair remotely by phone or at tsc.lv, etsc.ee and ltsc.lt, and those who, after handing a device in at a counter, later paid an invoice online, asked for a credit invoice or amended their request. Customers who walked in, left the device and did nothing online were not affected. TSC also says the contents of the repaired devices were not touched, and that the other companies of the LMT group were not hit because TSC runs separate IT infrastructure.

7%of TSC customers had data taken
3countries where the chain runs service centres
2criminal cases: the February attack and TSC
5 yearsthe maximum term the suspect faces

How investigators got to him

The February case came first. Police were already looking into an attack on another company's website, studied the method and saw the same handwriting in the TSC break-in. With help from LMT's own security service and from CERT.LV, the national incident response team, the circumstances were checked quickly enough to tie the two cases together and place the suspect. On 15 September officers detained him and searched an address in Riga, where they found evidence of further attacks on companies in Latvia and abroad. Those are still being investigated.

"This person worked alone. The goal was to get the data, prove to the company that he had done it, and extort money," said Jānis Markuns, who heads the first division of the State Police cybercrime department. He added that the man is not behind the two loudest Latvian hacks of this year, the ransomware attack on the state forestry company and the road authority breach.

The method was not targeted at all. Police say he ran an automated attack tool that scanned assorted websites for vulnerabilities, and whatever it found became the victim. Once inside he exported the database, including restricted data, used masking tools to hide his real location, and then wrote to the company from an anonymous mailbox created for the purpose, demanding payment for not publishing what he had. Neither the police nor the company disclosed the sum. Before this, he worked in IT. He is a suspect in both cases under three sections of the Criminal Law: unauthorised access to an automated data processing system for gain, extortion, and interference with such a system and unlawful handling of the information in it.

  1. The first attack in the case, on another Latvian company's website.
  2. The same method hits the TSC website and its repair database.
  3. TSC publishes its statement; about 7% of customers affected, the site is back online.
  4. Police detain a man born in 2003 and search an address in Riga.
  5. The State Police make the arrest public and describe both cases.
What is not settled: police say the stolen data has not reached third parties, but that is their assessment today, not a guarantee. TSC has not given an absolute number of affected customers, the ransom demand has not been disclosed, and the man is a suspect, not a convicted offender.

Why an unlock code is worse than an email address

A leaked email address is an annoyance. A leaked passcode is a key, and it stays a key until you change it. The same record can carry the IMEI, the model, your name and your phone number, which is everything a caller needs to sound exactly like the service centre that has your device: they know what you brought in, when, and for how much. That is the difference between spam and a call you are inclined to believe.

TSC's own advice is blunt: anyone who entered a screen unlock code or a home door code in a repair request should change both immediately. The company also reminds customers that its staff never call or text to ask you to confirm a Smart-ID or eParaksts request, to read out passwords, or to make an urgent payment. That warning is not boilerplate here, because the leaked fields are exactly what makes such a call convincing.

The third serious hack in Latvia in a few months

This lands in a country that has had a rough year. In June ransomware hit Latvian State Forests. In August the Road Traffic Safety Directorate lost data on 1.2 million people, close to two thirds of the population, including identity numbers, plate numbers and addresses; its supervisory board resigned and its chief announced he would go too. On 1 September the Consumer Rights Protection Centre leaked contact details of 697 business representatives and 34 of its own officials. TSC, CERT.LV notes, is not critical infrastructure at all. The scanning runs on its own and does not care how important a company is.

"You can see characteristics of a similar nature here, where fields containing a vulnerability are scanned automatically, so it is important to know all the resources that face outward and to react very quickly," said CERT.LV expert Kārlis Svilans. TSC notified the Data State Inspectorate, law enforcement and CERT.LV, brought in independent security specialists, audited the site's source code, closed the holes it found, added detection of suspicious activity and started cutting down how much customer data it keeps at all. On money, director Jānis Ducmanis was careful: "It is too early to talk about compensation, but we will assess each case individually." Elsewhere in Europe regulators have already started fining suppliers for exactly this kind of failure, as Sweden did over a leak at an HR contractor serving most of the country's municipalities. Latvians who went through the road authority breach already know the drill, including the wave of fake fines that followed it.

What a VPN does and does not do here

The suspect used masking tools to hide where he was sitting, and investigators identified him anyway, working from the pattern of the attacks rather than a single address. Worth stating plainly: privacy tools are legal and useful, but they are not immunity, and an investigation looks at the whole picture.

For customers the honest answer is that a VPN changes nothing about this leak. It encrypts the traffic between your device and the network, which does not reach a database sitting at a company you already handed your data to. What helps there is giving less of it in the first place, leaving the passcode field empty when a form asks for something it does not need, and changing the codes you did hand over.

What to do if you have handed a device in for repair

TSC is not the only one doing this. Repair forms everywhere ask for more than they need, and the answers sit in a database for years. This is a good week to go through your own list.

  • Change the screen unlock code on any device you have handed in for repair, and do it again after you collect it
  • If you gave a building or entrance door code to a courier, change it with your neighbours
  • Check the account you used to pay a repair invoice for payments you did not make
  • Treat calls that know your device, your repair and your name as suspicious by default, and call the company back on the number from its website
  • Never confirm a Smart-ID or eParaksts request you did not start yourself
  • Next time, leave the passcode and the door code out of the form unless the repair genuinely cannot proceed without them
I brought my device to a TSC counter. Am I affected?
According to the company, no, provided you did nothing online afterwards. The leak covers requests that went through the website: remote bookings, online invoice payments, credit invoice requests and amendments to a request.
How do I find out what exactly leaked about me?
TSC says it is assessing cases individually and has published contact information for customers. You also have the right to ask any company for a copy of the personal data it holds on you, and the answer tells you which fields were in the record.
The phone is still being repaired. Should I change the code now?
You cannot change the passcode of a device you do not have. Change it as soon as you collect it, and change the building door code now if you gave one, because that one does not depend on the phone.
Can customers claim compensation?
TSC's director says it is too early for that and that each case will be looked at individually. The company has notified the Data State Inspectorate, and the supervisor is the one that will rule on how the data was handled.
Would a VPN have prevented this?
No. The data was taken from the company's own database, not from your connection. A VPN protects traffic in transit; it has no effect on records a business already stores about you.

latviatsclmtdata breachpersonal datapasswordssmartphonesimeiextortionhackingpolicearrestsphishingcybersecuritydata protectionvpn

Read also