Cyberattack on LVM: criminal case launched against security expert Strazdiņš

State police have initiated a criminal case against cybersecurity expert Elvīs Strazdiņš in connection with a cyberattack on Latvia's state forestry IT infrastructure. The hacker is demanding approximately 618,600 euros for data decryption.

Cyberattack on LVM: criminal case launched against security expert Strazdiņš

Police launch criminal case against expert Strazdiņš — LVM hacker demands 618,600 euros

State police have initiated a preliminary investigation within a criminal case against software engineer and cybersecurity expert Elvīs Strazdiņš, reports apollo.lv. The reason is a cyberattack on "Latvijas valsts meži" (LVM) information technology infrastructure and related public activities.

Police informed social media that in connection with the cyberattack that occurred, it was established that a person not directly related to the incident had arbitrarily and without authorisation posed as an LVM representative — acting on behalf of a state institution without any authority to do so.

Late on Monday evening, Strazdiņš wrote on the platform X: "I'm out. This was a long day. Unfortunately, the law forbids me from saying anything more."

Strazdiņš published correspondence with hacker

Over the past weekend, Strazdiņš explained on his social media and YouTube channel how the attack on LVM servers had occurred. In a video, he published correspondence with the cybercriminal who carried out the attack, who has demanded 600,000 euros for data decryption.

Strazdiņš emphasised that legally this does not count as extortion, because the hacker has not directly approached LVM and has not demanded a ransom, but in other communication channels where the hacker has disclosed information about the attack, he has called on people to contact him.

According to Strazdiņš, the hacker is demanding 0.1% of the company's total revenue for LVM data decryption. According to LVM's 2025 report, LVM's total revenue last year was 618.6 million euros — meaning the requested sum amounts to 618,600 euros.

Vulnerability dating from 2019, backup copies deleted

In an interview with Latvian Television's programme "Panorāma", Strazdiņš explained that the hacker had exploited a software vulnerability that had not been updated for seven years. "The main thing he started with was 'GEO', which had a two-year-old vulnerability that should have been fixed. From what I know from inside information, the latest version should have been installed on almost all servers, but it remained on one server [the old version]. This server was then used," Strazdiņš said.

One of the vulnerabilities exploited was dated 2019 — meaning the relevant software had not been updated for six to seven years. The attacker also left malware on the servers. According to "Panorāma" reports, the hacker not only encrypted all data but also deleted backup copies.

Strazdiņš pointed out that in his post on his hacker forum, in which he described the attack, the hacker clearly indicated that in order to recover the encrypted data, he must be contacted. "He has also left his Signal and other platform contacts. Therefore he is demanding a ransom. That is how he lives," Strazdiņš emphasised. He suggested that the attacker could attempt to sell the obtained information to countries hostile to Latvia.

Cert.lv: commercially motivated attack

The cybersecurity incident prevention institution Cert.lv informed the LETA agency that responsibility for the attack has been claimed by a foreign financially motivated ransomware group, which has carried out similar activities against companies and state institutions in other countries.

Cert.lv director Baiba Kaškina pointed out that what happened could be a commercially motivated attack. The attacker does not hide particularly — although his identity is not known, he has described his activities on hacker forums, boasting about his "trophies".

LVM has already stated that the company has no intention of paying a ransom under any circumstances, and emphasised that all files in LVM IT systems had had backup copies. The company has turned to State police, and a criminal case for cyberattack has been initiated.

IT system restoration continues

LVM IT infrastructure and development director Māris Kuzmins informed the LETA agency on Friday that the IT team is gradually restoring the company's internal system operations to ensure business continuity. Some systems are already available, whilst in the next phase systems for communication with partners and clients will be restored, as well as the "LVM GEO" and "Mednis" applications.

Since the beginning of the incident, external IT systems — "LVM GEO", the map service system and the hunting application "Mednis", which serves hikers, hunters and forest industry workers daily — have been switched off for security reasons. Several internal systems ensuring information exchange with service providers and clients have also been switched off.

LVM was registered in 1999. The company's share capital is 525.989 million euros, the sole owner is the state, and the shareholder is the Ministry of Agriculture. LVM's turnover in 2025 reached 604.585 million euros — 3.2% more than a year earlier — whilst profit increased by 37.7%, reaching 206.73 million euros.

Source: Google News LV — Crime (lv)

Read this article in the original language