Cyberattacks are no longer an exception in Latvia. Are companies truly prepared?

Terry Fixter

By Terry Fixter, Chief Operating Officer, Kevlar Defense.

Only a few years ago, cyberattacks were widely perceived as a problem affecting major technology companies or government institutions. That is no longer the case. Events in Latvia over the past few weeks clearly demonstrate that any organization whose disruption would significantly affect customers, partners, or society can become a target.

On 22 June, a cyberattack against the IT infrastructure of Latvijas valsts meži (LVM) disrupted several public-facing services, including the LVM GEO mapping platform, mapping systems, and the Mednis hunting application. The attackers reportedly demanded a ransom exceeding €600,000 in exchange for decrypting the data. Only a few days later, it emerged that the same threat group had also gained access to the servers of pharmaceutical manufacturer Olpha (formerly Olainfarm).[5]

Both incidents reveal the same underlying mistake that we encounter in almost every serious cyber incident we investigate. The greatest problem is not necessarily insufficient protection. The greatest problem is the assumption that an attack will be detected in time.

These are not isolated events. They form part of a much broader trend unfolding across Europe.

The latest threat landscape report published by the European Union Agency for Cybersecurity (ENISA) analysed 4,875 significant cybersecurity incidents between July 2024 and June 2025.[1] Its conclusion is clear: ransomware remains Europe’s most destructive cyber threat, increasingly overlapping with organized cybercrime, state-sponsored cyber operations, and hacktivist campaigns.[1]

The Baltic States Are Attractive Targets for More Than Geographic Reasons

The Baltic countries are among Europe’s leaders in digitalisation. Public administration, financial services, manufacturing, and businesses increasingly rely on cloud infrastructure, digital identity, and interconnected information systems.

This digital transformation is a key driver of economic competitiveness.

At the same time, however, it dramatically expands the number of potential attack surfaces. The Baltic region also occupies a geopolitically sensitive position, where financially motivated cybercriminals operate alongside sophisticated state-sponsored threat actors.

According to ENISA, the sectors most frequently targeted within the European Union include public administration (38.2%), transport (7.5%), digital infrastructure (4.8%), financial services (4.5%), and manufacturing (2.9%). More than half (53.7%) of all analysed incidents affected organisations that fall under the enhanced cybersecurity obligations introduced by the NIS2 Directive.[1] NIS2 establishes mandatory cybersecurity requirements for critical infrastructure operators as well as many medium-sized and large enterprises across the European Union.

It is precisely this combination of advanced digitalisation and geopolitical exposure that makes the Baltic region particularly attractive to cyber attackers.

Attackers Have Become More Professional

Our incident response teams around the world assist in more than one hundred serious ransomware and data extortion cases every year. One lesson repeats itself almost every time.

Companies are rarely surprised that they have been attacked.

What surprises them most is discovering that the attackers had already been inside their networks for days, weeks, or even months before anyone detected them.

Modern cyberattacks no longer resemble chaotic attempts by individual hackers to breach systems. They have evolved into highly organised operations in which different specialist groups focus on initial access, lateral movement, data theft, ransomware deployment, and ransom negotiations.

Five years ago, we much more frequently encountered attacks whose primary objective was simply to disrupt business operations.

Today, almost every major incident begins with attackers identifying what is most valuable to the organisation—confidential data, customer information, intellectual property, or financial systems.

European data confirms the same trend. ENISA estimates that approximately 60% of cyber incidents begin with phishing, while 21.3% exploit known but unpatched software vulnerabilities.[1] Meanwhile, CERT-EU identified 174 active threat groups during 2025—64 more than the previous year—and notes that unpatched internet-facing infrastructure, including firewalls, VPN gateways, and other perimeter devices, remains the most common initial point of compromise.[3]

In other words, cyberattacks often begin not with sophisticated technical exploits, but with people or weaknesses in everyday organisational processes.

What This Means for Business

Business leaders have traditionally viewed cybersecurity as a cost centre.

Yet following a serious cyber incident, the largest costs rarely come from rebuilding servers.

They come from interrupted operations, lost customer confidence, contractual penalties, regulatory scrutiny, and reputational damage.

Data Has Become More Valuable Than Servers

Only a few years ago, attackers focused primarily on disrupting business operations as quickly as possible.

Today, information has become the most valuable asset.

Attackers typically attempt to steal confidential documents, customer records, financial information, or intellectual property before deploying ransomware or other extortion techniques.

If an organisation refuses to pay, attackers increasingly threaten to publish sensitive information, contact customers and business partners directly, or leak confidential business information online.

In many cases, reputational damage and loss of customer trust ultimately cost organisations far more than the technical recovery itself.

In LVM’s case, attackers had already leaked at least 44 gigabytes of data, while the total volume of compromised information remains under investigation.[5]

Latvia’s Experience Mirrors Europe’s Findings

Following the LVM incident, CERT.LV published updated recommendations for strengthening cybersecurity resilience.[4]

Notably, the guidance does not simply encourage organisations to purchase additional security products.

Instead, three recommendations stand out:

  • Maintain a complete inventory of all internet-facing and internal IT assets, together with their patch status—organisations cannot protect systems they do not know they have.
  • Implement multi-factor authentication for every publicly accessible service requiring user authentication, without exceptions.
  • Segment networks and adopt Zero Trust principles by assuming that a breach may already have occurred.[4]

These recommendations align closely with cybersecurity developments across Europe.

Europe Is Focusing on Resilience, Not Just Protection

This is precisely why the European Union is implementing the NIS2 Directive.

Its objective is not to force organisations to purchase more cybersecurity technology.

Instead, it requires company leadership to take direct responsibility for cyber risk management, incident preparedness, supply chain security, and business continuity.

Cybersecurity is becoming a corporate governance issue.

CERT-EU reaches similar conclusions in its latest threat assessment. During 2025, the cyber threat landscape became considerably more complex, with social engineering expanding beyond email into voice phishing, AI-generated deepfakes, and OAuth abuse. The number of software products actively exploited by attackers increased by approximately 80% during the year. Among CERT-EU’s primary recommendations are implementing phishing-resistant multi-factor authentication and prioritising the protection of internet-facing network infrastructure.[3]

The Biggest Mistake: Believing Your Company Is Too Small

One misconception remains remarkably common.

Many organisations believe they are simply too small to become cyberattack targets.

Cybercriminals disagree.

They automate reconnaissance and select victims based on opportunity rather than company size.

A compromised employee email account, an outdated VPN gateway, or a delayed security update is often far more valuable to attackers than the organisation’s annual revenue.

This explains why so many attacks begin with what appears to be a relatively minor incident—a compromised employee mailbox.

Attackers then quietly observe internal communications for days or even weeks, intercept invoices, modify payment instructions, and prepare the next phase of the attack.

This brings us back to the central point:

The real challenge is not whether an attack is possible.

The real challenge is whether an organisation can detect it before significant damage occurs.

Five Questions Every Executive Should Ask Today

The recent incidents in Latvia are not a reason for panic.

They are a reason to prepare.

Every executive should be able to answer five essential questions:

  • Do we have a complete inventory of every system accessible from the internet?
  • Is multi-factor authentication enabled across all critical services?
  • Have our backup systems been tested through actual recovery exercises rather than simply created?
  • Could we detect an attacker before ransomware is deployed?
  • Does senior management know exactly what to do during the first 24 hours after a major cyber incident?

If even one of these questions cannot be answered confidently, the organisation’s resilience is probably lower than its leadership assumes.

According to CERT.LV, since Russia’s full-scale invasion of Ukraine in 2022, the number of registered cyber incidents in Latvia has increased sixfold, while the number of compromised devices identified has increased eightfold. During the first quarter of 2026 alone, CERT.LV manually handled 846 cyber incidents and identified more than 757,000 compromised devices—the highest figure recorded to date.[2]

This demonstrates that cybersecurity is no longer a temporary crisis.

It has become the new normal.

Today, the winners are not the organisations that never experience cyberattacks.

They are the organisations that detect attacks first, contain them quickly, and restore operations rapidly.

The question is no longer whether a company will experience a cyber incident.

The question is how prepared it will be on the day that it does.

Increasingly, that level of preparedness determines which organisations emerge stronger from a crisis—and which spend years trying to rebuild customer trust.

References

[1] European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025. 1 October 2025.
https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025

European Union Agency for Cybersecurity (ENISA). EU consistently targeted by diverse yet convergent threat groups (Press Release). 1 October 2025.
https://www.enisa.europa.eu/news/etl-2025-eu-consistently-targeted-by-diverse-yet-convergent-threat-groups

[2] CERT.LV. The Latvian Cyberspace in the First Quarter of 2026. 15 May 2026.
https://www.cert.gov.lv/lv/2026/05/2026-gada-1-ceturksnis-latvijas-kibertelpa

[3] CERT-EU. Threat Landscape Report 2025 – A Year in Review. 8 April 2026.
https://cert.europa.eu/publications/threat-intelligence/tlr2025/

[4] CERT.LV. CERT.LV Recommendations for Improving Infrastructure Cybersecurity Resilience Against Cyberattacks. 3 July 2026.
https://cert.lv/lv/2026/07/cert-lv-rekomendacijas-infrastrukturas-kiberdrosibas-noturibas-uzlabosanai-pret-kiberuzbrukumiem

[5] LETA News Agency reports and media coverage published by LSM.lvTVNETApollo.lv, and NRA.lv concerning the cyberattacks against Latvijas valsts meži (LVM) and Olpha, June–July 2026.

Source: mmnews.eu

Share this article

related News

EURO

Trending

Tallinn

loader-image
temperature icon 20°C
overcast clouds
Wind Gust: 21 Km/h
Clouds: 100%

Riga

loader-image
temperature icon 19°C
overcast clouds
Wind Gust: 7 Km/h
Clouds: 100%

Vilnius

loader-image
temperature icon 22°C
broken clouds
Wind Gust: 3 Km/h
Clouds: 70%