Cybersecurity expert Strazdiņš liable for interfering with investigation of LVM hacker attack
State police have established that a cybersecurity expert impersonated an LVM representative without authority and negotiated with a hacker regarding a ransom payment. Criminal proceedings have been initiated against him.

Police initiate criminal proceedings against expert who negotiated with LVM hacker
State police have announced that cybersecurity expert Elviss Strazdiņš impersonated a representative of Latvian State Forests (LVM) without any authority and conducted unauthorised communications with a cybercriminal regarding a ransom payment for data decryption. According to jauns.lv, these actions were not coordinated with any of the institutions involved in resolving the incident.
"A person, acting in the name of a state institution without any authority, conducted activities including communication with a cybercriminal, initiating negotiations regarding a potential ransom payment for data decryption," police stated. The investigation is being conducted within the framework of a previously initiated criminal proceeding — concerning the cyberattack on LVM infrastructure. No person has been detained.
Police have emphasised that no person has the right to arbitrarily interfere in an investigation process or impersonate a representative of the affected organisation, as this could affect the course of the investigation, hinder the gathering of evidence, or cause irreversible consequences. At the same time, it was noted that police have not refused to provide assistance in uncovering criminal offences, but no one has contacted law enforcement in this matter.
Strazdiņš: "Instead of thanking me, criminal proceedings were initiated against me"
Strazdiņš announced the initiation of criminal proceedings on the microblogging platform "X". "I'm exhausted. It's been a long day. Unfortunately the law prevents me from saying anything more," he wrote.
In the previous week, the expert published a video explaining how attackers gained access to LVM systems. The first vulnerability exploited was outdated "GeoServer" software, which LVM uses for processing geospatial data. To demonstrate the attack mechanism, Strazdiņš installed an identical version of the software on his home server and replicated the attack sequence — proving that with a specially crafted request it is possible not only to create files on the server, but also to obtain a user password file and send it to another server. According to him, some of the passwords could be decrypted within minutes.
In the video, Strazdiņš also disclosed the contents of correspondence with the hacker. The cyber attacker demanded 600,000 euros for data decryption and access restoration — approximately 0.1% of LVM's turnover. The hacker also offered a "discount": reducing the sum to 500,000 euros if payment were made through the "Monero" platform. Strazdiņš's attempts to negotiate a lower amount were unsuccessful.
According to the hacker's claims, approximately 400 GB of data from LVM's internal document system, 20 GB of data from four "GitLab" servers containing software source code, and 60 GB of data containing employee email information came into their possession. When asked about further sale of the stolen data, the hacker responded that LVM data was not of particular interest to anyone.
Public reaction — police criticised
The police announcement provoked a series of negative comments. "They can't do anything themselves, but when a person points out their inaction, mistakes, etc., they initiate an investigation against them," wrote one commenter. "Complete nonsense. First police initiate a criminal case and later complain that people don't want to cooperate with police!!! Is that a normal attitude?" asked another.
LVM: ransom will not be paid, backups preserved
LVM has previously announced that the company will under no circumstances pay a ransom. All files in LVM's IT systems have backup copies. Māris Kuzmins, the IT infrastructure and development director, announced that the IT team is gradually restoring the operation of internal systems to ensure continuity of business operations.
Responsibility for the attack has been claimed by a foreign financially motivated ransomware group that has conducted similar activities against enterprises and institutions in other countries, LETA agency was informed by "Cert.lv", the cyber incident prevention institution.
LVM is a state-owned enterprise whose sole shareholder is the Latvian state, with the share holder being the Ministry of Agriculture. The company was registered in 1999 with share capital of 525.989 million euros and manages state-owned forest lands. LVM's turnover in 2025 reached 604.585 million euros — 3.2% more than the previous year — whilst profit increased by 37.7%, reaching 206.73 million euros.
Source: Google News LV — Crime (lv)