Cyber Incident Victim: Corruption Prevention and Combating Bureau
Date:
Jul 2022
Location:
Latvia
Summary
A cyber attack targeted Latvia's Corruption Prevention and Combating Bureau, disrupting public access to its electronic data entry systems, political party financing databases, and official mobile application. The distributed denial-of-service (DDoS) attack overwhelmed resources with excessive fake requests, rendering them temporarily inaccessible. Latvian cybersecurity authorities attributed the incident to groups supporting Russia's aggressive policies and confirmed no compromise of stored data. Response efforts involved collaboration with the national IT security incident team to restore services, alongside recommendations for enhanced protective measures against such attacks.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 25, 2022, Latvia’s Corruption Prevention and Combating Bureau (KNAB) experienced a cyber attack targeting multiple institutional resources. The attack occurred in the evening and disrupted public accessibility to KNAB’s Electronic Data Entry Systems, political parties’ financing databases, and the official mobile application Ziņo KNAB. KNAB confirmed the incident resulted in service interruptions but emphasized that all stored data within the affected databases remained secure. The bureau did not specify the exact duration of the outage or the number of systems compromised beyond the named resources. Information Technology Security Incident Response Institution of Latvia (Cert.lv) collaborated with KNAB to investigate and mitigate the attack, initiating restoration efforts shortly after detection.

Cert.lv representative Līga Besere attributed the attack to groups supporting Russia’s aggressive policies, identifying the method as a distributed denial-of-service (DDoS) attack. The attackers overwhelmed KNAB’s systems with high volumes of fraudulent access requests, rendering targeted resources temporarily inaccessible. Besere noted that such attacks typically focus on single targets due to the substantial resources required to sustain them. KNAB and Cert.lv implemented countermeasures to restore service availability, though no specific timeline for full recovery was disclosed. Cert.lv also provided KNAB with security recommendations to strengthen database protections against future incidents. The disruption impacted public access to critical anti-corruption tools, though no data breaches or permanent system damage was reported.
