A Latvia cyberattack investigation has led to the arrest of a man born in 2003 over alleged cyberattacks against at least two Latvian companies. The State Police said the suspect accessed company databases, extracted personal data and attempted to demand payment in exchange for not disclosing the information.
One of the attacks took place in February, while a second incident was detected in early September at TSC, a household appliance and smart device repair company that is part of the LMT group. Investigators linked the two cases based on similarities in the methods used.
Latvia Cyberattack Investigation Links Two Cases
According to the State Police, the attacker used an automated tool to scan websites for vulnerabilities. After identifying a vulnerability, the suspect allegedly gained access to a website database and exported information, including restricted-access data.
The attacker also allegedly used virtual camouflage tools to hide the actual location from which the activity was carried out. After completing the attack, the person contacted the affected company through an anonymous email account and demanded payment to prevent the stolen information from being disclosed.
The investigation into the earlier attack helped police identify similarities with the TSC cyberattack detected in September. The State Police worked with LMT Security Service and CERT.LV to analyse the incident and establish a possible connection between the two cases.
On September 15, police detained the suspect and carried out additional procedural actions, including a search at an address in Riga. Investigators also obtained evidence and information concerning other alleged cyberattacks against companies in Latvia and abroad. Those investigations are continuing.
TSC Cyberattack Exposed Customer Repair Data
TSC disclosed the data breach earlier this month after unidentified attackers exploited a vulnerability on its website and accessed a database containing information related to customer repair orders.
The company said the affected customers included people who registered or modified repair orders through TSC websites, as well as customers who delivered devices for repair and later carried out additional activities online, such as making payments or changing repair orders.
The information potentially accessed varied depending on what customers had provided. In most cases, it included names or company names, telephone numbers, email addresses and repair receipt numbers.
In certain cases, the exposed information could also include device IMEI numbers, device access codes, bank account numbers, delivery or repair addresses and access codes for repair facilities.
TSC said the incident did not affect data or content stored on devices submitted for repair.
Hacker Arrested as Investigation Continues
The State Police said there is reason to believe its prompt response prevented the unauthorized personal data from being passed to third parties. Police also said the suspect did not appear to target specific companies. Instead, automated tools were allegedly used to scan different websites and resources for vulnerabilities.
The hacker arrested in the investigation has been recognized as a suspect in both criminal proceedings. Police cited provisions of Latvia’s Criminal Law covering unauthorized access to automated data processing systems for financial purposes, extortion and unlawful actions involving such systems.
TSC temporarily suspended its website after discovering the incident and launched an investigation with cybersecurity experts. Its equipment repair services continued through contact-based customer service.
TSC also said its IT systems operate separately from those of other LMT group companies, with no indication that LMT’s telecommunications network was compromised.
The criminal investigation remains ongoing. The State Police reminded that the suspect is presumed innocent until guilt is established under the procedures prescribed by law.






































