Cyber attack on LVM: Strazdiņš investigated over unauthorised LVM representation
State Police are investigating cybersecurity expert Elvīs Strazdiņš after he acted without authority on behalf of LVM. Hackers are demanding approximately 618,600 euros for data decryption.

Police: certain person posed as LVM representative without authorisation
The State Police have launched an investigation into software engineer and cybersecurity expert Elvīs Strazdiņš in connection with a criminal case concerning a cyber attack on the infrastructure of "Latvijas valsts meži" (LVM), as reported by apollo.lv. Police announced on social media that a person unrelated to the attack had "arbitrarily and without authorisation posed as an LVM representative", carrying out actions on behalf of state institutions without any mandate.
Strazdiņš himself posted on the platform X on Monday evening that he could not comment further on what was happening. "I'm out. This was a long day. Unfortunately, the law forbids me from saying anything more," he stated.
Strazdiņš publicly explained the course of the attack
Over the past weekend, Strazdiņš published lists on his social media accounts and YouTube channel of the hacker who carried out the cyber attack, demanding 600,000 euros for data decryption. In the Latvian Television programme "Panorāma", Strazdiņš explained that the attacker had exploited a series of vulnerabilities in various software applications.
"The main one he started with was 'GEO', which had a two-year-old vulnerability that should have been fixed. From what I know from internal information, the latest version appears to have been installed on almost all servers, but one server was left with [the old version]. This server was then used," said Strazdiņš.
He added that one of the vulnerabilities exploited was dated 2019 — meaning that the software had not been updated for seven years. Furthermore, the attacker had also left malware on the servers.
Hacker demands 0.1% of LVM revenue
Strazdiņš notes that by personally communicating with the hacker, he found out that the ransom amount is 0.1% of LVM's total revenue. According to LVM's 2025 report, the company's total revenue last year was 618.6 million euros, meaning the requested sum amounts to 618,600 euros.
Strazdiņš indicated that legally this situation does not constitute extortion, as the hacker has not directly approached LVM with a ransom demand, but on other communication channels — including a hacker forum where he has boasted about "trophies" — has invited contact with him. "He has also left his Signal and other platform contacts. Thereby he is demanding ransom. That is how he lives," Strazdiņš emphasised.
He also suggested that the attacker, who is motivated by money, could not rule out the possibility of attempting to sell the obtained information to countries unfavourable to Latvia.
LVM: backup copies exist, ransom will not be paid
Reporting by "Panorāma" reveals that the hacker not only encrypted all data but also deleted backup copies. LVM previously told the news agency LETA that the company would under no circumstances pay ransom and that all files in IT systems had backup copies — however, these statements partly contradict what "Panorāma" has reported.
Responsibility for the attack has been claimed by a foreign financially motivated ransomware group that has carried out similar actions against companies and state institutions in other countries, the cyber incident prevention institute "Cert.lv" informed the news agency LETA. Baiba Kaškina, head of "Cert.lv", stated that what happened could be a commercially motivated attack.
System restoration continues
On Friday, Māris Kuzmins, LVM's IT infrastructure and development director, informed the news agency LETA that the IT team is gradually restoring the company's internal system operations. Some systems are already available, whilst in the next phase systems will be restored that enable communication with partner organisations and clients, as well as the applications "LVM GEO" and "Mednis", which are used by recreational visitors, hunters and forest sector workers.
Since the beginning of the incident, external IT systems maintained by LVM have not been available for security reasons — "LVM GEO", the map service system, and the hunting application "Mednis". Several internal systems that enable information exchange with service providers and clients have also been switched off.
LVM has approached the State Police, and police have launched a criminal case concerning the cyber attack. The company was registered in 1999, with the state as its sole owner, and the Ministry of Agriculture as the shareholder. LVM's turnover in 2025 was 604.585 million euros — 3.2% more than the previous year — while profit increased by 37.7%, reaching 206.73 million euros.
Source: Google News LV — Crime (lv)