Latvia's state-owned forestry company LVM is still restoring systems weeks after a ransomware attack knocked customer and contractor services offline. Latvian authorities said the attackers likely spent more than a week in the network and exploited an unpatched vulnerability in software that had not been updated for two years. CERT.LV said about 44 GB of data was leaked, including internal documents, email, code repositories, digital certificates, cryptographic keys, and user credentials.
Why it matters: This is a significant ransomware and data-theft incident affecting a major state-owned enterprise, with possible downstream risk from leaked credentials and cryptographic material. Organizations in Latvia, especially public-sector and state-linked entities, should review exposure, rotate affected secrets and certificates, and urgently patch internet-facing systems.
2026.07.09
100% relevant
This article establishes the core facts of the LVM ransomware event: prolonged service disruption, likely initial access through a long-unpatched vulnerability, exfiltration and public leakage of sensitive data, and attribution by Latvian authorities to a foreign financially motivated ransomware group.
← Back to all stories