The Consumer Rights Protection Center of Latvia (PTAC) reported a possible data security incident in one of the information systems under its management.
The incident affected the remote statistical data collection system ASDIS, which PTAC uses to oversee licensed enterprises. It falls into the category of systems with the lowest risk level and meets the minimum cybersecurity requirements established in Latvia.
Preliminary investigations revealed that the incident resulted in the acquisition of contact information for representatives of companies providing consumer credit services, out-of-court debt collection, and comprehensive travel services.
In total, the data concerns 697 representatives of enterprises and 34 officials from PTAC — including names, surnames, email addresses, and phone numbers. PTAC notes that a significant portion of this information is already available in public state registers, particularly on the Open Data Portal.
At the same time, according to PTAC, the information that enterprises provided to the agency for oversight purposes was not compromised as a result of the incident.
The ASDIS system is currently disabled, and all its users have been notified by PTAC about its temporary unavailability.
PTAC also reported that the system is located within a network infrastructure equipped with the CERT.LV early warning sensor system. The agency emphasizes the need for additional investments in the protection of state information resources amid the unstable geopolitical situation.
Leave a comment