Over the weekend of 8–9 August 2026, attackers compromised Latvia’s Road Traffic Safety Directorate — the Ceļu satiksmes drošības direkcija, or CSDD — the state agency that registers every vehicle in the country, issues every driving licence, and takes payment for both. The agency first publicly acknowledged the incident on 13 August. On 14 August, officials still could not say what had been taken. On 18 August the full scope arrived: payment receipt data going back to 2008, covering more than 1.2 million individuals and roughly 200,000 businesses and legal entities.
Latvia’s population is about 1.8 to 1.9 million people. The exposed dataset therefore describes, on any reasonable reading, something in the order of two-thirds of the country’s residents.
On Wednesday 19 August 2026 — six days after the first public admission — the entire management board of CSDD resigned. The agency’s head, Aivars Aksenoks, had already signalled he would step down. Around 20 August, Latvia’s president asked for a prosecutor’s review of the affair.
There is a specific reason this deserves close reading beyond the Baltic press. Latvia’s National Cybersecurity Law (Nacionālās kiberdrošības likums), transposing the NIS2 Directive, entered into force on 1 September 2024 — nearly two years before the attack, and ahead of most of the EU. The obligations were not aspirational, not pending transposition, not subject to a grace period: they were live domestic law binding a public administration entity squarely inside NIS2’s essential-entity scope. That sequence — live NIS2 obligations, a whole-population data loss, an outsourced monitoring provider that reportedly did not see it, and a board that resigned en masse — makes CSDD the clearest public-sector management-accountability case of 2026 so far.
What Was Taken, and Why “Payment Records” Understates It
The exposed dataset is described as payment receipt data, which sounds innocuous until you enumerate the fields:
- Personal identification numbers (the Latvian personal code) for individuals, and registration numbers for legal entities
- Names and surnames, or company names
- Payment amounts
- Payment dates
- Vehicle registration numbers
- Addresses
That is not a payments log. It is a longitudinal identity graph of a national population, built over eighteen years, binding a permanent state identifier to a legal name, an address, and a specific vehicle, and timestamping the relationship — so it also encodes address and vehicle history. A personal code bound to a verified name, a current address, and a registered vehicle is a knowledge-based-authentication bypass kit for any organisation that still verifies identity by asking questions only the data subject should be able to answer. In a country of under two million people, 1.2 million such bindings do not merely enable fraud against individuals; they degrade the reliability of identity verification as a national practice.
The Article 20 Problem: Management Bodies Are Named in the Statute
Most of what organisations call “NIS2 compliance” is Article 21 work. Article 20 is shorter, less discussed, and the one that reached CSDD’s boardroom.
Article 20(1) requires Member States to ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken to comply with Article 21, oversee their implementation, and — the operative clause — can be held liable for infringements. This is not a delegation-friendly provision. It does not say the CISO approves and the board is informed; it names the management body as the approving authority and attaches liability to that role.
Article 20(2) goes further and requires members of management bodies to follow training, so that management acquires sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices. The drafters anticipated exactly the defence boards offer after an incident — we relied on the technical staff, we are not security people — and pre-emptively removed it.
A whole board resigning within six days of disclosure is, functionally, what Article 20 was drafted to produce. Whether the resignations were legally compelled, politically forced, or voluntarily offered is beside the point for compliance purposes. The signal to every other public-sector management body in the EU is that the post-incident question is no longer “which vendor failed?” but “who approved the risk-management measures, on what basis, and what did they do to verify implementation?”
Be precise about what that liability looks like, because the directive is not uniform. Article 32(6) lets Member States temporarily suspend individuals discharging managerial responsibilities at chief-executive or legal-representative level in essential entities that fail to remedy an infringement — while also letting them exclude public administration entities from parts of the enforcement regime. Latvia’s outcome was reputational and political rather than a formal sanction, and it arrived faster than any regulatory process could have: in the public sector, the mechanism that actually bites is resignation under political pressure, not a fine that moves money between state budgets.
The pattern repeated when Romania’s ANCPI land registry was wiped: the entity is systemically important, the data is national in scope, and enforcement tools designed for private companies map awkwardly onto a government agency.
The Monitoring Provider: You Can Outsource Detection, Not Accountability
CSDD’s external security monitoring provider reportedly failed to detect the breach. That single fact carries more compliance weight than anything else in the technical account, because it lands on three separate NIS2 provisions at once.
Article 21(2)(d) — supply chain security. Entities must address security in the supply chain, including security-related aspects of relationships with direct suppliers and service providers. A managed detection and response provider is not a peripheral supplier; it is the entity’s detection capability, and the adequacy of that contract is the adequacy of the detection control. Article 21(3) sharpens this: entities must take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers — an affirmative duty to evaluate the supplier’s own security quality, not to accept a service description and a monthly report.
Article 21(2)(b) — incident handling. A detection failure is an incident-handling failure: if the monitoring service did not surface the intrusion, incident handling did not begin until someone noticed the consequences — the worst possible starting position for the Article 23 clocks.
The governance failure is familiar. An organisation procures monitoring, the service produces dashboards and monthly summaries, and the board reads the summaries as assurance. But a monitoring contract is a promise to look, not a guarantee of seeing. The concrete questions — which log sources are in scope, what the contractual detection and escalation time is and whether anyone measures it, who tests that alerts fire, what happens when the provider misses something — rarely appear in a managed-security statement of work unless the buyer insists. When the buyer is a state agency procuring under rules rewarding lowest compliant price, the incentive is to buy the cheapest service satisfying a checkbox labelled “24/7 monitoring.” That checkbox is what CSDD’s board approved, and what Article 20 makes them answerable for.
The multi-party version of this problem — one processor, many controllers, who owes what to whom — is worked through in our analysis of the Ceva Logistics breach and its ten controllers.
Mapping the Timeline Against the Article 23 Clock
NIS2 Article 23 sets a staged reporting cadence for significant incidents, running from awareness:
- Within 24 hours — an early warning to the CSIRT or competent authority, indicating whether the incident is suspected of being caused by unlawful or malicious acts, or could have cross-border impact.
- Within 72 hours — an incident notification updating the early warning with an initial assessment of severity and impact, plus indicators of compromise where available.
- Within one month of the incident notification — a final report with a detailed description, the likely root cause, mitigation applied, and any cross-border impact.
The critical analytical move is to separate notification to the CSIRT from communication to the public: different provisions, different clocks. Nothing in the public record tells us when CSDD notified Latvia’s CSIRT, and the 24-hour early warning may well have been met even though the public heard nothing until day five. A gap in public communication is not, by itself, evidence of an Article 23 breach.
What Article 23 does say about the public is in Article 23(7): the CSIRT or competent authority may require the entity to inform the public where public awareness is necessary to prevent or deal with an ongoing incident, and may itself do so after consulting the entity. Public communication under NIS2 is a risk-mitigation instrument, triggered by necessity and often authority-directed — not a general transparency duty on the 24/72-hour clock.
The uncomfortable part of the CSDD timeline is therefore not the four days to first admission. It is the five further days to scope disclosure, during which the agency’s public position was “something happened but we cannot say what” — the interval in which 1.2 million people could have been taking protective steps and were instead waiting, and in which the incident stopped being a technical event and became a political one.
On how the October 2026 milestones and management liability interlock, see our NIS2 October 2026 deadline and DORA management-liability readiness briefing.
The GDPR Track Runs in Parallel, Not in Sequence
NIS2 reporting does not discharge data protection obligations, and this is where the CSDD timeline gets harder to defend.
GDPR Article 33(1) requires the controller to notify the competent supervisory authority — here, Datu valsts inspekcija (DVI), Latvia’s Data State Inspectorate — of a personal data breach without undue delay and, where feasible, not later than 72 hours after having become aware of it, with reasons where that window is missed. Two clarifications organisations routinely get wrong:
The clock runs from awareness, not from certainty. Under EDPB guidance inherited from the Article 29 Working Party, a controller becomes “aware” when it has a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised — not when forensics conclude. A short initial investigation period is permitted, measured in hours, not a week.
Article 33(4) exists precisely for the CSDD situation. Where information cannot be provided at once, it may be provided in phases without undue further delay — the defensible route for an entity that knows it has lost data but cannot yet quantify it: notify within 72 hours with what you have, flag the unknowns, supplement. Waiting until the picture is complete before saying anything is exactly what Article 33(4) was written to make unnecessary, and it is what the public-facing timeline suggests happened.
Article 34 then requires communication to data subjects without undue delay, in plain language, where a breach is likely to result in a high risk to rights and freedoms — which a dataset binding permanent national identifiers to names, addresses, and vehicles for two-thirds of a country plainly is. The Article 34(3)(c) escape valve for disproportionate effort was in substance used, but it still requires the public communication to be equally effective, a bar a day-ten press statement struggles to meet.
Entities keep treating these regimes as one workflow. They are not: the two notifications have separate recipients, separate content, and separate clocks, both starting on awareness — and the one that gets missed is usually the data protection one.
Permanent Identifiers: The Harm That Does Not Expire
The single most consequential technical fact about this breach is that a Latvian personal code cannot be reissued the way a payment card can.
The whole apparatus of breach response for financial data rests on reissuance: the issuer cancels the card, mails a new one, and the exposed number is worthless within days. National identification numbers have no half-life. A personal code is issued once, used across banking, healthcare, employment, taxation, property, and public services, and persists for life. When 1.2 million are exposed alongside verified names and addresses, no remediation restores the prior state — the state cannot reissue two-thirds of its identifiers without invalidating every downstream record referencing them.
The consequences fall hardest on KYC and identity verification in a small national market:
- Knowledge-based verification degrades immediately. Any bank, telecom, insurer, or public service that authenticates a caller by asking for a personal code plus an address or vehicle detail has had its question bank published. The response is not to warn staff to be careful; it is to retire those factors from authentication entirely.
- Synthetic identity fraud becomes cheap. A real personal code with an altered name and a controlled address is the classic synthetic construction, and in a market of 1.9 million the statistical fraud-detection baselines large-country institutions rely on are far thinner.
- eIDAS and national eID implications are real but bounded. A leaked personal code does not compromise a Latvian eID credential, which rests on cryptographic keys and PINs. The identifier is the username, not the password — but that holds only where relying parties enforce it. Under eIDAS and the emerging EUDI Wallet regime, this breach is an argument for retiring knowledge-based fallbacks in favour of wallet-based verification, precisely because the knowledge factors are now public.
The instruction for regulated entities in Latvia and its neighbours is narrow and urgent: treat the personal code as an identifier, never an authenticator, and audit every process where that line has blurred.
Public Administration as an Essential Entity: Scope Without Budget
NIS2 Annex I lists sectors of high criticality and includes public administration entities of central government as defined by each Member State, with regional and local coverage at Member State discretion. Latvia’s transposition brings agencies like CSDD within scope, which is why the Article 20 and 21 analysis applies at all.
Here is the structural problem every EU government should read as a warning. A state vehicle registry holds a dataset with the risk profile of a systemically important financial institution and the security budget of a mid-sized administrative agency. The concentration follows from the statutory mandate — CSDD holds payment records for the entire driving population because it is the only body that can register a vehicle — while the funding follows from a budget line where it competes with road maintenance and licence-testing capacity.
NIS2 fixes the obligations; it does not fix that asymmetry. The Article 21 baseline assumes an entity that can resource it, and for a registry agency several of those controls must come through central-government shared services or they will not come at all. The baseline such registries need:
- Retention limits enforced technically, not by policy. Payment receipts from 2008 were in a live-accessible system in 2026. GDPR Article 5(1)(e) storage limitation is not merely a privacy principle; it is a blast-radius control. Eighteen years of records in one queryable store turned a breach into a national event.
- Segmentation between the operational registry and the payments history, so compromise of one does not yield the other.
- Bulk-egress alerting on any query or export exceeding a defined record count — the highest-value detection for registry systems, and trivial to implement relative to its value.
- Field-level encryption of stored identifiers, so a database compromise does not yield plaintext personal codes.
Comparable incidents — including the Swiss Federal Office of Information Technology SharePoint compromise — point the same way: government entities are targeted as data aggregators, and that aggregation is a policy decision carrying a security cost nobody priced when the mandate was written.
Governance Checklist for Management Bodies
If you sit on the board of an essential or important entity — especially a public one — the CSDD case converts into questions you should be able to answer from your own minutes:
- Can you point to the dated board resolution approving your Article 21 measures, and the document set it approved? Approval existing only as a briefing note is not approval.
- Have all management body members completed cybersecurity training, and is it recorded? Article 20(2) is explicit, and it is the easiest provision in the directive for a regulator to check.
- For every outsourced security function, who internally owns the outcome? Name the person. If the answer is the vendor, you have outsourced accountability, which Article 20 does not permit.
- What is your detection coverage map, and when was it last tested by someone trying to trigger an alert?
- Do you have a dual-track notification playbook running the Article 23 CSIRT clock and the Article 33 DPA clock in parallel, with named owners and a pre-agreed trigger for Article 33(4) phased notification — plus a pre-cleared public statement template for a breach of unknown scope?
- Do you know what your Member State’s transposition says about management liability, including any public-sector carve-out from Article 32(6)? Latvia’s board did not wait to find out.
Conclusion
The CSDD breach will be remembered for the resignation, not the intrusion, and that is the right emphasis. Technically this looks unremarkable: a database that held more than it needed to for longer than it should have, at an organisation whose outsourced monitoring did not catch the intrusion. What is not unremarkable is the governance response. Six days from public admission to the resignation of an entire management board compresses the accountability cycle in a way that would have been unthinkable in the public sector a decade ago — and it happened in a Member State with NIS2 obligations in force since 1 September 2024. The directive did not have to be enforced for its logic to operate: the existence of a legal framework naming management bodies as approvers and overseers of cybersecurity measures changed what a board could plausibly say after a failure. “The IT department handled that” stopped being available as an answer.
Read the Latvian sequence as a preview rather than an anomaly. The obligations are personal, the timelines are short, the parallel GDPR track is unforgiving, and the data your organisation has quietly accumulated since 2008 determines how bad the day gets. Retention policy, supplier oversight, and a documented approval trail are not administrative hygiene — they are the three things that decide whether the board survives the breach.
Sources: LSM — Personal data of over one million people compromised in CSDD cyberattack (18.08.2026), LSM — Entire CSDD board resigns (19.08.2026), The Record — Latvia cyberattack hits vehicle registry data, BNN — Latvia CSDD cyberattack coverage, Xinhua — Latvian president seeks prosecutor’s review of CSDD data breach (20.08.2026)
This article is provided for informational purposes only and does not constitute legal advice.



