State Police launches investigation into cybersecurity expert Strazdins in LVM attack case
State Police has established that an unrelated person illegally impersonated an LVM representative. Cybersecurity expert Elviss Strazdins says he cannot comment on ongoing proceedings.

Police comment on criminal proceedings against Strazdins within LVM cyber attack framework
State Police has launched an investigation into software engineer and cybersecurity expert Elviss Strazdins in connection with criminal proceedings concerning a cyber attack on "Latvijas valsts mežu" (LVM) infrastructure. As reported by Apollo, police announced on social media that an unrelated person has been identified who arbitrarily and without authorisation impersonated an LVM representative — taking actions on behalf of a state institution without any mandate.
Strazdins himself wrote on platform X on Monday evening: "I'm out. It was a long day. Unfortunately, the law forbids me from telling anything more."
Strazdins publicly explained the course of the attack
At the end of last week, Strazdins publicly outlined on his social media and YouTube channel how the hacker attack on LVM servers occurred. He also published a list of the hacker who carried out the cyber attack, who demanded 600,000 euros for decrypting the data.
Strazdins explained in Latvia's Television programme "Panorama" that the hacker exploited a software vulnerability that had not been updated for seven years. "The main thing he started with was 'GEO', which contained a two-year-old vulnerability that should have been fixed. An old version remained on one server. This server is what was then exploited," Strazdins said.
Furthermore, one of the exploited vulnerabilities was dated to 2019, indicating that the software had not been updated for seven years. Strazdins also noted that the attacker left malware on the servers.
Hacker demanded 0.1% of LVM revenue
Strazdins personally contacted the hacker and ascertained that the demanded ransom sum was 0.1% of LVM's total revenue. According to information available in LVM's 2025 report, LVM's total revenue last year was 618.6 million euros — accordingly, the hacker is demanding 618,600 euros.
The legal situation is unclear: Strazdins explained that this does not formally constitute extortion, since the hacker has not directly approached LVM and has not demanded a ransom for the encrypted data. However, on other communication channels where the hacker described the attack, he called for contact to be made with him. "He has also left his Signal and other platform contacts. In this way, he is demanding a ransom. This is how he operates," Strazdins emphasised.
Strazdins also suggested that the attacker, who is motivated by money, could attempt to sell the obtained information to countries hostile to Latvia.
LVM will not pay ransom and is restoring systems
LVM informed news agency LETA that the company has no plans under any circumstances to pay a ransom or anything similar. LVM also indicated that all files stored in IT systems have backup copies — however, according to information provided by the programme "Panorama", the hacker not only encrypted all data but also deleted backup copies.
Responsibility for the attack has been claimed by a foreign financially motivated ransomware group, the cyber incident prevention institution Cert.lv informed news agency LETA. This group has carried out similar activities against companies and state institutions in other countries.
LVM IT infrastructure and development director Māris Kuzmins announced on Friday that the IT team is gradually restoring the operation of the company's internal systems. Some systems are already accessible; systems for communication with partners and clients, as well as applications "LVM GEO" and "Mednis", which are used by hikers, hunters and forestry workers, will subsequently be restored.
Since the start of the incident, external IT infrastructure has been shut down for security reasons — the map services system "LVM GEO" and hunting application "Mednis", as well as several internal systems.
Cert.lv: likely commercially motivated attack
Cert.lv head Baiba Kaškina indicated that what occurred could be a commercially motivated attack. The attacker described his activities on a hacker forum, where he boasted about his "trophies", although his identity is unknown. In a similar manner, he has attacked other companies elsewhere in the world.
LVM has turned to State Police regarding the cyber attack, and police have launched criminal proceedings. LVM's turnover in 2025 was 604.585 million euros — 3.2% more than a year previously — whilst profit increased by 37.7%, reaching 206.73 million euros. The company was registered in 1999, its sole owner is the state, and the shareholder is the Ministry of Agriculture.
Source: Apollo