FacebookX / TwitterLinkedinThreads

With particular attention to data security, the Consumer Rights Protection Centre (CRPC) informs the public of a recently identified data security incident affecting one of the information systems under the CRPC’s responsibility.

The affected information system is the Remote Statistical Data Retrieval System (ASDIS). ASDIS is classified as a Category C security system, which represents the lowest risk level for information systems. The CRPC uses this system to support the supervision of licensed businesses, and it complies with the minimum cybersecurity requirements established in Latvia.

ASDIS is hosted within a network infrastructure equipped with a CERT.LV Early Warning Sensor (ABS) system. Given the current unstable geopolitical environment, the CRPC considers it essential to strengthen the security of all technological resources and to allocate the necessary funding for this purpose. The Ministry of Economics has previously highlighted this need during Cabinet discussions on cybersecurity matters.

The investigation conducted so far indicates that, as a result of the incident, contact information relating to entities licensed by the CRPC, namely providers of consumer credit services, providers of out-of-court debt recovery services, and providers of package travel services, was extracted.

The extracted data includes the contact information of 697 representatives of commercial entities and 34 CRPC officials, specifically their first name, surname, email address, and telephone number. In most cases, this information is already available through other public registers, such as the Open Data Portal.

The incident has not compromised any supervisory data submitted to the CRPC by businesses.

The affected system has currently been taken offline. The CRPC immediately informed all users of the system about its unavailability.