What the CSDD and LVM Cyberattacks Teach Businesses: Four Cybersecurity Lessons

Latvia's Road Traffic Safety Directorate (CSDD) and the state forestry company Latvijas valsts meži (LVM) were both breached in 2026, and neither attack came through Microsoft or another large cloud platform. Both came through systems the organisations ran themselves. At CSDD it was "Medical", a platform CSDD built in-house, where doctors enter drivers' medical certificates and which needed nothing more than a username and password. At LVM it was a server that had not been updated for two years. The result: data on 1.2 million people and 44 GB of internal information leaked.
The attacks worried far more than the public sector. According to Google data, "kiberuzbrukums" (Latvian for "cyberattack") is normally searched about 20 times a month in Latvia. In June, after the LVM attack, it was searched 4,400 times, and in August, after CSDD, 1,900 times (Google Ads Keyword Planner, MS Solutions analysis). For business owners the obvious question is: could this happen to us?
This article covers what exactly happened, four lessons a business can take from it, and why documents and applications in your own Microsoft 365 are a safer choice than one more server or one more separate application.
What happened at CSDD
The attack on CSDD took place on 8–10 August 2026 and was made public on 13 August. The attackers obtained personal data of 1.2 million people and about 150,000 company registration numbers: names, personal identification codes, addresses, payment details and vehicle registration plates. Customers' usernames and passwords were not affected (LSM, CERT.LV).
According to Tet, the Latvian telecom operator that manages CSDD's network, the attacker got in through "Medical", a platform about 200 doctors use to enter medical certificates. It could be accessed with a username and password. Tet was not responsible for the security of applications CSDD developed itself and did not receive that platform's logs, so the intrusion could not be detected (LSM). CSDD's board resigned after the attack.
What happened at LVM
On 11 June 2026 an attacker broke into GeoServer, an internal system LVM uses to process geospatial data. The system had not been updated for at least two years. CERT.LV, Latvia's national incident response team, had warned about the vulnerability, but LVM misread the "≥" (greater than or equal to) sign and concluded that its version was not affected (LSM).
The active phase began on 22 June, with data being encrypted and stolen. LVM shut down its entire IT infrastructure. The attacker published 44 GB of data: internal documents, emails with attachments, source code, system keys and passwords (NRA). Restoring almost all systems took about two months.
Four lessons for businesses
In neither case did the attacker use sophisticated, previously unknown techniques. They found a door the organisation had built itself and had not guarded well enough.
1. Every system you run yourself is one more door
CSDD's "Medical" platform and LVM's GeoServer were separate systems, each with its own sign-in, its own updates and its own person responsible. The more such systems, the more doors someone has to watch every day. In a typical company these are an old document server, a separate contracts application, a SaaS tool for invoices and a few Excel files in a shared folder.
2. A password alone is not enough
At CSDD a username and password were enough. Passwords get stolen, guessed and leaked. Multi-factor authentication (a second confirmation on your phone) makes a stolen password largely useless. But it has to be switched on in every system separately, and older or in-house applications often don't support it at all.
3. Updates must not depend on someone reading an email correctly
LVM did receive the warning. The mistake was a single mathematical sign. As long as people patch servers by hand, the same mistake can happen in any company, especially where IT is one person or an outside contractor.
4. If nobody sees the logs, nobody notices the attack
Tet did not receive the CSDD platform's logs, so the intrusion went undetected. When responsibility is split between several vendors, each sees only their own part. The attacker only needs the part nobody sees.
Why your own Microsoft 365 is the safer place for your data
Many companies already use Microsoft 365 for email and documents, so the security foundation is already paid for. The real question is whether your other applications and documents live there too, or are scattered across separate servers and vendors.
One door for everything. When document management, a contract register or a CRM is built in your Microsoft 365 environment, employees sign in with the same Microsoft account they use for email. There is no separate password for each application. When someone leaves, blocking one account closes access to everything at once.
Multi-factor authentication in one place. A Microsoft 365 administrator can switch on multi-factor authentication for all users and all applications at once. That is exactly the protection CSDD's platform lacked, where a username and password were enough.
Microsoft keeps the platform updated. Nobody in your company has to patch SharePoint, Teams or the rest of Microsoft 365. An LVM-style situation, where a server runs for years with a known vulnerability, cannot happen, because you simply don't have that server.
One audit log. The Microsoft 365 audit log is on by default and keeps records of user and admin activity for 180 days (Microsoft Learn). Everything is visible in one place instead of being split between vendors.
Your data stays yours, and stays in the EU. Documents and applications live in your company's own Microsoft 365 environment (your tenant), not on yet another SaaS vendor's servers. Since February 2025 the Microsoft EU Data Boundary ensures that European customers' Microsoft 365, Dynamics 365 and Power Platform data is stored and processed in the EU and EFTA (Microsoft).
Independent assessment. Analyst firm Gartner has named Microsoft a Leader in Access Management nine times, in Endpoint Protection Platforms for the sixth year in a row (2025) and in Security Information and Event Management (SIEM) in 2025 (Microsoft).
To be fair: Microsoft 365 is not secure by itself. Multi-factor authentication has to be switched on, access rights granted with care, and external sharing controlled. But that is one set of settings in one place, not ten different systems with ten different people responsible.
What Latvia's National Cybersecurity Law says
Latvia's National Cybersecurity Law (Nacionālās kiberdrošības likums) has been in force since 1 September 2024 and transposes the EU NIS2 Directive (likumi.lv). It applies to medium-sized and large companies in many sectors, including energy, transport, healthcare, digital services, food production, manufacturing, trade and waste management. These companies must manage cybersecurity risks, appoint a cybersecurity manager and report incidents.
The fewer separate systems you have, the easier these requirements are to meet. One access management, one audit log and one platform vendor are far easier to describe, monitor and prove than a scattered landscape of systems.
How to start
- List your doors. Write down every system that holds company documents or customer data, and for each one note where it runs, how people sign in and who updates it.
- Switch on multi-factor authentication in Microsoft 365 for all users, if you haven't already.
- Move documents and processes into your own Microsoft 365. Document management, approvals and registers can run in SharePoint with the same sign-in your employees already use.
- Close the doors you don't need. Every server or application you no longer need is one risk fewer.
MS Solutions builds document management, CRM and other business solutions directly in your Microsoft 365 environment. No separate servers and no third-party SaaS platforms, with the same Microsoft sign-in and central access management. All your data and applications stay yours.
Frequently asked questions
How many doors does your company's data have?
We'll look at where your documents and applications live today and show you how to bring them together in one secure Microsoft 365 environment.