Latvia arrests a hacker who took device unlock codes from a repair chain's database
On 23 September Latvia's State Police said they had detained a 23-year-old man in Riga on suspicion of breaking into the websites of at least two Latvian companies and demanding money to stay quiet. One of the victims is TSC, the repair arm of the LMT telecoms group, which fixes phones, smart devices and household appliances in Latvia, Lithuania and Estonia.
The leak itself surfaced on 11 September. TSC said roughly 7% of its customers were affected, and the names and phone numbers are the least of it. For some people the repair database also held the unlock passcode of the device they handed in, its IMEI, a bank account number and the entrance code of their building.
In short
- The suspect, born in 2003, was detained on 15 September; police made it public on 23 September.
- He got into the database behind the repair request form on tsc.lv. About 7% of customers were affected.
- Beyond names and contacts, some records held device passcodes, IMEI numbers, bank accounts, delivery addresses and building door codes.
- Police say the data was not passed on to anyone else. The man faces up to five years.
What actually leaked
According to TSC's own statement, the attacker used a vulnerability on the company website and reached the database that stores repair requests. For most customers the stolen set is dull and familiar: first and last name or company name, phone number, email address, repair receipt number. In part of the records it goes much further, because the repair form asks for it: the IMEI of the device, the passcode that unlocks the device handed in for repair, bank account numbers and personal identity codes used for settlements, delivery addresses, and the entrance door code of the building where a courier was supposed to collect the item.
The leak covers customers whose requests went through the website: people who booked a repair remotely by phone or at tsc.lv, etsc.ee and ltsc.lt, and those who, after handing a device in at a counter, later paid an invoice online, asked for a credit invoice or amended their request. Customers who walked in, left the device and did nothing online were not affected. TSC also says the contents of the repaired devices were not touched, and that the other companies of the LMT group were not hit because TSC runs separate IT infrastructure.
How investigators got to him
The February case came first. Police were already looking into an attack on another company's website, studied the method and saw the same handwriting in the TSC break-in. With help from LMT's own security service and from CERT.LV, the national incident response team, the circumstances were checked quickly enough to tie the two cases together and place the suspect. On 15 September officers detained him and searched an address in Riga, where they found evidence of further attacks on companies in Latvia and abroad. Those are still being investigated.
"This person worked alone. The goal was to get the data, prove to the company that he had done it, and extort money," said Jānis Markuns, who heads the first division of the State Police cybercrime department. He added that the man is not behind the two loudest Latvian hacks of this year, the ransomware attack on the state forestry company and the road authority breach.
The method was not targeted at all. Police say he ran an automated attack tool that scanned assorted websites for vulnerabilities, and whatever it found became the victim. Once inside he exported the database, including restricted data, used masking tools to hide his real location, and then wrote to the company from an anonymous mailbox created for the purpose, demanding payment for not publishing what he had. Neither the police nor the company disclosed the sum. Before this, he worked in IT. He is a suspect in both cases under three sections of the Criminal Law: unauthorised access to an automated data processing system for gain, extortion, and interference with such a system and unlawful handling of the information in it.
- The first attack in the case, on another Latvian company's website.
- The same method hits the TSC website and its repair database.
- TSC publishes its statement; about 7% of customers affected, the site is back online.
- Police detain a man born in 2003 and search an address in Riga.
- The State Police make the arrest public and describe both cases.
Why an unlock code is worse than an email address
A leaked email address is an annoyance. A leaked passcode is a key, and it stays a key until you change it. The same record can carry the IMEI, the model, your name and your phone number, which is everything a caller needs to sound exactly like the service centre that has your device: they know what you brought in, when, and for how much. That is the difference between spam and a call you are inclined to believe.
TSC's own advice is blunt: anyone who entered a screen unlock code or a home door code in a repair request should change both immediately. The company also reminds customers that its staff never call or text to ask you to confirm a Smart-ID or eParaksts request, to read out passwords, or to make an urgent payment. That warning is not boilerplate here, because the leaked fields are exactly what makes such a call convincing.
The third serious hack in Latvia in a few months
This lands in a country that has had a rough year. In June ransomware hit Latvian State Forests. In August the Road Traffic Safety Directorate lost data on 1.2 million people, close to two thirds of the population, including identity numbers, plate numbers and addresses; its supervisory board resigned and its chief announced he would go too. On 1 September the Consumer Rights Protection Centre leaked contact details of 697 business representatives and 34 of its own officials. TSC, CERT.LV notes, is not critical infrastructure at all. The scanning runs on its own and does not care how important a company is.
"You can see characteristics of a similar nature here, where fields containing a vulnerability are scanned automatically, so it is important to know all the resources that face outward and to react very quickly," said CERT.LV expert Kārlis Svilans. TSC notified the Data State Inspectorate, law enforcement and CERT.LV, brought in independent security specialists, audited the site's source code, closed the holes it found, added detection of suspicious activity and started cutting down how much customer data it keeps at all. On money, director Jānis Ducmanis was careful: "It is too early to talk about compensation, but we will assess each case individually." Elsewhere in Europe regulators have already started fining suppliers for exactly this kind of failure, as Sweden did over a leak at an HR contractor serving most of the country's municipalities. Latvians who went through the road authority breach already know the drill, including the wave of fake fines that followed it.
What a VPN does and does not do here
The suspect used masking tools to hide where he was sitting, and investigators identified him anyway, working from the pattern of the attacks rather than a single address. Worth stating plainly: privacy tools are legal and useful, but they are not immunity, and an investigation looks at the whole picture.
For customers the honest answer is that a VPN changes nothing about this leak. It encrypts the traffic between your device and the network, which does not reach a database sitting at a company you already handed your data to. What helps there is giving less of it in the first place, leaving the passcode field empty when a form asks for something it does not need, and changing the codes you did hand over.
What to do if you have handed a device in for repair
TSC is not the only one doing this. Repair forms everywhere ask for more than they need, and the answers sit in a database for years. This is a good week to go through your own list.
- Change the screen unlock code on any device you have handed in for repair, and do it again after you collect it
- If you gave a building or entrance door code to a courier, change it with your neighbours
- Check the account you used to pay a repair invoice for payments you did not make
- Treat calls that know your device, your repair and your name as suspicious by default, and call the company back on the number from its website
- Never confirm a Smart-ID or eParaksts request you did not start yourself
- Next time, leave the passcode and the door code out of the form unless the repair genuinely cannot proceed without them
I brought my device to a TSC counter. Am I affected?
How do I find out what exactly leaked about me?
The phone is still being repaired. Should I change the code now?
Can customers claim compensation?
Would a VPN have prevented this?
• Aizturēts hakeris par kiberuzbrukumiem vismaz diviem Latvijas uzņēmumiem mantkārīgā nolūkā - LSM.lv
• Hacker detained in Latvia for at least two cyberattacks - LSM English
• Latvia arrests suspected hacker for electronics repair company breach - The Record
• Kiberuzbrukumā viedierīču remonta uzņēmumam «TSC» iegūti ap 7 % klientu datu - LSM.lv
• «TSC» piedzīvojis kiberuzbrukumu - noplūduši klientu dati un ierīču piekļuves kodi - Kursors.lv
• Latvian officials resign after cyberattack exposes data on 1.2 million people - The Record
• Another hack in Latvia, more public data leaked - LSM English