Skip to main content
Back to overview
Medium

Latvijas Valsts Mezi (LVM) Suffers Cybersecurity Breach

Cybersecurity breach reveals vulnerability of Latvia's strategic infrastructure: minister RIGA, June 26 (Xinhua) -- A recent incident in which hackers managed to access IT systems of Latvia's state-owned company…

Key points

  • Cybersecurity breach of IT systems.
  • External and internal systems taken offline.
  • Foreign ransomware group claimed responsibility.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Service Disruption

Availability

Published
Jun 26, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Availability

Mentioned entities

LvmLatvijas Valsts MeziLVMLatviaRIGAXinhuaSmart Administration and Regional DevelopmentMinister Edgars TavarsFriday. TheTV3

Quick context

Questions about this signal

What happened in this signal?

Cybersecurity breach reveals vulnerability of Latvia's strategic infrastructure: minister RIGA, June 26 (Xinhua) -- A recent incident in which hackers managed to access IT systems of Latvia's state-owned company Latvijas Valsts Mezi (LVM) revealed the relative vulnerability of the country's strategic infrastructure, Smart Administration and Regional Development Minister Edgars Tavars said Friday. The cybersecurity breach in LVM has caused particular concerns because the company has been entrusted with developing an electoral IT platform for Latvia's parliamentary elections, which are scheduled to take place this fall. In an interview with the TV3 channel on Friday, Tavars called on all state institutions to identify cybersecurity flaws in their own systems and learn a lession from the LVM incident. The minister believes, though, that in general, Latvian IT specialists are good enough to prevent similar incidents from repeating in the future. Tavars said that the electronic voter register, on which LVM has been working, was completed before the incident and was not at risk. In general, "we are definitely not ringing alarm bells about the elections," the minister said. LVM discovered the cybersecurity breach of its IT systems last weekend. In response, the company took all its external IT systems offline and also shut down some internal communication systems. A foreign ransomware group, which has carried out similar attacks against companies and government agencies in other countries, has claimed responsibility on the cyberattack on LVM. Cyberattack on Latvian State Forests detected LVM is one of three companies developing this year’s Saeima election system . However, the company noted that the development of the election system was kept separate and was not affected. Security measures will be reviewed as a precaution. The cyberattack occurred on Monday, June 22. According to the company, since the incident began, the external information technology (IT) systems maintained by LVM, including “LVM GEO,” the mapping service system, and the hunting app “Mednis”, have been shut down and are unavailable for security reasons. Several of LVM’s internal systems, which facilitate the company’s exchange of information with service providers and clients, have also been taken offline. LVM spokesperson Tomass Kotovičs stated that the threat has been eliminated, but it will take time to restore the systems to operation. Baiba Kaškina, head of “Cert.lv,” explained that the attack was thwarted immediately. According to her, there is no reason to believe that it was specifically targeted at Latvia. “Cert.lv” is inclined to believe that this was a commercially motivated attack aimed at demanding a ransom and demonstrating the attackers’ capabilities. The State Police Cybercrime Combating Directorate, based on publicly available information, has launched an internal investigation on its own initiative to clarify the circumstances of the incident and identify the possible perpetrator, according to the LETA news agency. Select text and press Ctrl+Enter to send a suggested correction to the editor Select text and press Report a mistake to send a suggested correction to the editor

When was this signal reported?

Shadow Tier lists Jun 26, 2026 as the signal date.

Which organization is connected to this signal?

Lvm is the organization connected to this public signal.

Explore Lvm
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to cyber service disruption intelligence based on its reported consequences.

Explore cyber service disruption intelligence