Menu
Browse
Date:

Jul 2022

Location:

Latvia

Summary

A cyber attack targeted Latvia's Corruption Prevention and Combating Bureau, disrupting public access to its electronic data entry systems, political party financing databases, and official mobile application. The distributed denial-of-service (DDoS) attack overwhelmed resources with excessive fake requests, rendering them temporarily inaccessible. Latvian cybersecurity authorities attributed the incident to groups supporting Russia's aggressive policies and confirmed no compromise of stored data. Response efforts involved collaboration with the national IT security incident team to restore services, alongside recommendations for enhanced protective measures against such attacks.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 25, 2022, Latvia’s Corruption Prevention and Combating Bureau (KNAB) experienced a cyber attack targeting multiple institutional resources. The attack occurred in the evening and disrupted public accessibility to KNAB’s Electronic Data Entry Systems, political parties’ financing databases, and the official mobile application Ziņo KNAB. KNAB confirmed the incident resulted in service interruptions but emphasized that all stored data within the affected databases remained secure. The bureau did not specify the exact duration of the outage or the number of systems compromised beyond the named resources. Information Technology Security Incident Response Institution of Latvia (Cert.lv) collaborated with KNAB to investigate and mitigate the attack, initiating restoration efforts shortly after detection.

Cyber Incident Image

Cert.lv representative Līga Besere attributed the attack to groups supporting Russia’s aggressive policies, identifying the method as a distributed denial-of-service (DDoS) attack. The attackers overwhelmed KNAB’s systems with high volumes of fraudulent access requests, rendering targeted resources temporarily inaccessible. Besere noted that such attacks typically focus on single targets due to the substantial resources required to sustain them. KNAB and Cert.lv implemented countermeasures to restore service availability, though no specific timeline for full recovery was disclosed. Cert.lv also provided KNAB with security recommendations to strengthen database protections against future incidents. The disruption impacted public access to critical anti-corruption tools, though no data breaches or permanent system damage was reported.

Sources
Sources available to members
1 source