Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The Latvian State Police arrested a 23-year-old man, born in 2003 and residing in Riga, on September 15, 2026. He is suspected of carrying out at least two cyberattacks against local companies between February and September 2026, including TSC, an LMT Group company specializing in electronic device repair. The arrest came just six days after TSC publicly disclosed the breach on September 9 — an unusually tight window between disclosure and law-enforcement action that reflects effective coordination among police, the national CERT, and corporate security teams.
According to convergent reporting from The Record (Recorded Future News), the English service of public broadcaster LSM, and BNN-News, the suspect did not select specific targets. Instead, he used automated scanning tools to probe websites and online resources for security weaknesses, then exploited them to access backend databases and extract personal data. The method confirms an opportunistic pattern, not a targeted campaign against critical infrastructure.
- Arrest on September 15, 2026 of a man born in 2003; maximum potential sentence is five years in prison
- Two confirmed attacks: first in February 2026 against an unidentified company, second in early September against TSC
- Extracted data includes names, contacts, IBANs, addresses, device access codes, and building access codes
- Suspect attempted extortion via anonymous email; data does not appear to have been shared with third parties
The Method: Opportunistic Scanning and Web Vulnerabilities
The suspect acted with what Latvian police described as a non-targeted approach. The Record, citing official statements, reported the individual "used automated hacking tools to scan websites and other online resources for security weaknesses rather than targeting specific companies". LSM English confirms the same reconstruction: "no specific companies were targeted in the cyber-attacks; rather, automated attack tools were used to scan and search for vulnerabilities on various websites and resources".
The non-selective nature of the attack is significant for risk assessment: the victim became a target not because of strategic value but because of technical exposure. The dossier does not specify the exact vulnerability type exploited — whether SQL injection, path traversal, or another mechanism — nor the software or framework involved. This lack of specific technical detail is a significant limitation for anyone seeking to replicate a precise threat profile.
After gaining unauthorized access, the attacker extracted data from databases and then contacted victims via purpose-created anonymous email accounts, demanding payment to prevent disclosure. LSM English notes the email was "created specifically for this purpose", indicating a minimal level of operational planning but no infrastructure sophistication.
TSC and Repair Data: An Invisible Trust Chain
TSC, the second confirmed victim, operates in electronic device repair within the LMT Group, Latvia's largest telecommunications operator. The September 9, 2026 disclosure, published on ltsc.lt in Lithuanian, lists the categories of potentially compromised data: names, phone numbers, email addresses, device unlock codes for items submitted for repair, banking coordinates (IBAN), residential addresses, and — an element less common in standard breaches — building access codes.
This last category warrants attention. Building access codes, when collected in an electronics repair database, create a bridge between digital and physical attack surfaces, exposing victims not only to data disclosure but to real-world access scenarios. TSC clarified that its IT systems are separate from the LMT Group's telecommunications network and that the latter was not compromised. The distinction is technically relevant and slightly counter-intuitive: TSC belongs to the group but does not share its network infrastructure, suggesting an architectural segmentation that contained the blast radius.
The TSC statement does not quantify the exact number of affected customers, a figure that remains unknown in the dossier.
"The suspect used masking tools to hide their real location but was identified within six days of public disclosure."
The Hunt: Police, CERT, and Corporate Security Collaboration
The arrest within six days of TSC's disclosure resulted from documented collaboration among the State Police, CERT.LV, and LMT Security Service. According to LSM English and BNN-News, both investigative supports — the national CERT and the parent group's security team — contributed to the forensic reconstruction. The operational speed is notable compared to average identification times for non-APT actors in opportunistic attacks, where technical anonymity often holds for months.
The suspect attempted to conceal their identity through "virtual masking" — the term used by The Record — but this did not prevent identification. Police indicate the stolen data "does not appear to have been shared with third parties" (The Record: "does not appear to have been shared with third parties"; LSM: "it has not been passed on to third parties"; BNN: "suspect did not distribute the data obtained"), a triple convergence that makes this claim particularly solid despite the absence of an accessible primary government source in English.
The possibility of additional attacks remains open. The Record and LSM both report that investigations uncovered "evidence of possible attacks against other businesses in Latvia and abroad" and that authorities are gathering "information regarding other cyber-attacks carried out by the individual against various companies in Latvia and abroad". The number, scale, and location of these potential attacks are not quantified.
Why It Matters
The case raises three questions the dossier does not resolve and the sources do not directly address. First: the persistence of web vulnerabilities in seemingly low-profile infrastructure — electronics repair sites — that process high-sensitivity operational data (unlock codes, building access) but likely receive smaller security budgets than financial services. The brief does not document whether TSC conducted regular penetration testing or whether the vulnerability was known and unmitigated.
Second: the relationship between physical trust and digital trust. When a customer hands a smartphone with its unlock code to a repair center, that data enters a web database whose security perimeter is often invisible to the end user. The breach makes explicit a trust chain that consumers cannot evaluate ex ante.
Third: the brief does not specify whether the suspect acted independently or is part of a broader network, nor whether the speed of arrest reflects a technical takedown or a tip-off. These investigative limits condition the assessment of the Latvian threat landscape and its transnational connections.
Timeline and Legal Status
| February 2026 | First detected attack against unidentified company |
| September 9, 2026 | TSC publicly discloses breach |
| Early September 2026 | Second detected attack against TSC with same modus operandi |
| September 15, 2026 | Suspect arrested in Riga |
The dossier does not clarify whether the suspect has been formally charged or whether the arrest represents only an investigative detention. The maximum potential penalty cited by sources is five years in prison, but the actual sentence will depend on the outcome of investigations into potential additional attacks and the legal qualification of the extortion attempt.
The suspect's identity has not been made public, consistent with Latvian privacy norms for individuals under criminal investigation. The name of the first company hit likewise remains undisclosed.
Frequently Asked Questions
- Was the LMT network compromised?
- No. TSC explicitly stated that its IT systems are separate from the LMT Group's telecommunications network and that the latter was not compromised.
- What type of vulnerability was exploited?
- The dossier does not specify the technical mechanism. Sources refer generically to "vulnerabilities in websites" without identifying whether it was SQL injection, RCE, or another vector.
- Were the data published or sold?
- According to three convergent sources, the data does not appear to have been shared with third parties. The monetization attempt occurred via direct extortion of victims, not through sale on secondary markets.
Sources
- https://therecord.media/latvia-hacker-arrest-cyberattack
- https://eng.lsm.lv/article/society/crime/23.09.2026-hacker-detained-in-latvia-for-at-least-two-cyberattacks.a664394/
- https://bnn-news.com/hacker-arrested-over-cyberattacks-on-at-least-two-latvian-companies-284067
- https://www.vp.gov.lv/en/article/international-operation-simcartel-state-police-dismantles-it-infrastructure-used-online-fraud-five-latvian-nationals-arrested
- https://www.vp.gov.lv/lv/jaunums/aizturets-hakeris-par-veiktiem-kiberuzbrukumiem-vismaz-diviem-latvijas-uznemumiem-mantkariga-noluka
- https://www.ltsc.lt/lt/tsc-informacija/verta-zinoti/pranesimas
- https://www.recordedfuture.com/?utm_source=therecord&utm_medium=referral&utm_content=post-footer-ad
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.