Police investigate hacker attack on LVM; foreign ransomware gang claims responsibility
The State Police has launched an investigation into a cyber attack on joint-stock company Latvijas valsts meži (LVM). The attack was carried out by a foreign financially motivated ransomware gang, which has previously acted against companies in NATO and EU member states.

Police investigate hacker attack on LVM; foreign ransomware gang claims responsibility
Over the past holidays, joint-stock company Latvijas valsts meži (LVM) experienced a serious cybersecurity incident. The attackers gained access to the company's information technology systems and took control of the data. A foreign gang engaged in ransomware distribution has claimed responsibility for the attack, reports LETA, citing "Cert.lv".
The State Police's Cyber Crime Suppression Division has initiated criminal proceedings. These were opened under a provision that protects automated data processing systems containing information on state security. More details about the investigation are reported by Delfi.
The cybersecurity institution "Cert.lv" is currently assisting LVM in investigating the incident and mitigating its consequences. It is also analysing what information has been leaked in order to determine whether additional risks exist. Recommendations have been provided to the company and other parties involved on how to protect themselves from further threats.
LVM IT director Māris Kuzmins informed that the company's specialists are gradually restoring system operations. Some of them are already functioning, but others still need to be returned to operational order. Among these are platforms necessary for servicing collaboration partners and clients, as well as the "LVM GEO" and "Mednis" applications, which are used by outdoor recreation and hunting enthusiasts as well as forest industry specialists.
For security purposes, several external and internal systems have been temporarily shut down. "LVM GEO", the mapping service and hunting application "Mednis" are unavailable. Similarly, internal platforms that enable data exchange with service providers and consumers have been closed.
Cert.lv director Baiba Kašķina noted that the motive is likely profit. The attackers do not publicly deny their involvement — although their identities are unknown, they have boasted of their actions on hacker forums. This same collective has previously attacked other targets outside Latvia's borders, including companies in NATO and European Union countries. Cert.lv has also informed international partners about this.
The company has contacted law enforcement regarding the incident.
Source: TVNET