Menu
Browse

Cyber Incident Victim: Latvijas valsts meži

Date

Jun 2026

Location

Latvia

Status

Resolved

Updated

2026-08-17 20:29

Timeline
Occurred
Jun 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Undetermined
Summary

Latvijas valsts meži suffered a cyberattack that exploited a known vulnerability in its GeoServer system which had not been updated, leading to data encryption and theft of about 44 gigabytes of internal data including access keys, authentication data, employee information, and internal documents. The breach was traced to a misinterpretation of a security warning symbol, prompting the company to revise its notification handling procedures. After the incident, systems were largely restored and a broader review of government IT systems was initiated.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

The investigation by De facto (LTV) revealed that Latvijas valsts meži had been aware of a vulnerability in its information systems since 2024, but the required software update was never implemented. Cert.lv had issued a warning about the vulnerability, which the company’s IT infrastructure and development director Maris Kuzmins said was misinterpreted because the warning used the mathematical symbol '≥' to indicate the range of vulnerable software versions. Kuzmins stated that the mistake was on the company’s side, as they did not realize their version was affected. According to the deputy head of Cert.lv, Varis Teivans, the misinterpretation of the symbol likely led Latvijas valsts meži to conclude that its system was not among the vulnerable ones. The attacker or group known as ByteToBreach infiltrated the internal GeoServer system on June 11, using that foothold to gradually gain access to other internal resources. On June 22 the active phase of the attack commenced, involving encryption and theft of data. After the breach the criminals published the stolen information and provided a detailed account of their actions, mocking the company’s level of protection.

Cyber Incident Image

As a result of the attack approximately 44 gigabytes of internal data were stolen, and Cert.lv reported that the leaked material included access keys, authentication data, internal correspondence, employee information, infrastructure details and internal company documents. Analysis of the leak forced specialists to contact several owners of critical infrastructure facilities because the stolen data could potentially affect their systems. LVM’s IT infrastructure and development director Maris Kuzmins noted that before the incident vulnerability reports were checked using a ‘four eyes’ principle, but afterwards they are now analyzed by several specialists simultaneously. After the incident the company revised its internal procedures for handling security notifications. Almost all of Latvijas valsts meži’s information systems have been restored, and the company plans to conduct a comprehensive security audit once the IT infrastructure modernization is completed.

Experts observed that the problem extended beyond a single mistake, noting that unupdated components were present in several of the company’s information systems and that previous security checks had not identified the vulnerability because separate testing of the software complex had not been performed. Kirill Solovyev, head of the Possible Security group, emphasized that an information security audit should be carried out by an independent contractor, stating that the same team that developed the system cannot reliably spot obvious issues. The cyberattack renewed debate in Latvia about the role of white‑hat hackers, with new regulations for their activity under discussion, although industry representatives consider the proposed rules excessively strict. At the request of Prime Minister Andris Kulbergs, all ministries were required to assess the risks of their IT systems and prepare proposals for strengthening protection. Kirill Solovyev also pointed out that most successful cyberattacks still stem from untimely software updates, incomplete accounting of used information systems and human errors. Experts warned that the situation may become more complicated as artificial intelligence accelerates the search for vulnerabilities for both defenders and attackers, and Cert.lv did not rule out the possibility of a ‘vulnerability apocalypse’ in which new weaknesses are discovered faster than fixes can be released.

Sources
Sources available to members
2 sources