Infosecurity

Weeks After Ransomware Attack, Latvia’s State Forestry Giant Is Still Picking Up the Pieces

Published

on

Two-Thirds of Customers Still Locked Out

It has been weeks since the ransomware attack hit LVM, Latvia’s state-owned forestry behemoth. Yet the company admitted on Thursday that full recovery remains a distant goal. Chief Technology Officer Maris Kuzmins told local media this week that while the situation has stabilized, getting everything back to normal is proving “quite challenging.”

Roughly two-thirds of customers with active service contracts still cannot access the affected systems. That includes the company’s mapping platform, its hunting application, and the backend tools used to swap information with contractors. The attack, first disclosed in late June, knocked out a significant chunk of LVM’s digital infrastructure.

An Old Vulnerability, A Fast Intrusion

Kuzmins revealed that the attackers gained entry through a vulnerability in a system that had not been patched in two years. He did not name the specific software, but the admission raises uncomfortable questions about patch management at one of the country’s most profitable state-owned enterprises. Ransomware attack prevention often hinges on timely updates — and this case is a stark reminder of what happens when updates slip.

Latvian authorities said the intruders had likely been inside LVM’s network for more than a week before anyone noticed. By then, they had already stolen roughly 44 gigabytes of data, which they later dumped online. Investigators believe the attackers accessed far more information than they ultimately published. The leaked trove includes internal documents, email threads, software code repositories, digital certificates, cryptographic keys, and user credentials.

LVM previously stated it had not received a ransom demand and would refuse to pay even if one arrived.

Who Is Behind the Attack?

Latvia’s national computer emergency response team, CERT.LV, attributed the intrusion to a foreign, financially motivated ransomware group. The same group has previously targeted companies and public institutions in NATO and European Union countries. Officials have not named the group publicly.

CERT.LV warned that the threat actor “continues its activities in Latvian cyberspace, purposefully searching for new potential vulnerabilities in the infrastructures of public- and private-sector organizations.” That is not a vague warning — it is a specific alert that more attacks may be coming.

Election System: Safe, But Scrutinized

The attack drew extra scrutiny because LVM helped develop new functionality for Latvia’s electronic voter registration system — the tool that lets citizens cast ballots at any polling station. That raised obvious concerns about election integrity.

Latvian authorities moved quickly to reassure the public. The election software was developed in a completely separate environment, and its code was never stored in LVM’s corporate repositories. CERT.LV reviewed every software delivery made for that project and found no evidence of malicious code or unauthorized access. The system has been declared safe for the upcoming parliamentary elections.

A Second Breach, Same Threat Actor

CERT.LV also revealed that the same ransomware group compromised a server belonging to Olpha, a Latvian pharmaceutical company formerly known as Olainfarm. That breach has since been contained, with no evidence so far of broader damage beyond the affected server.

Authorities stressed that the two breaches were technically unrelated, despite being the work of the same threat actor. That suggests the group is casting a wide net across Latvia, probing both public and private sector targets for weaknesses.

What Comes Next for LVM?

LVM manages most of Latvia’s state forests, harvests and sells timber, maintains public recreation sites, and provides geographic information services. It is a cornerstone of the national economy. Restoring its systems is not just an IT problem — it affects contractors, customers, and public services.

Kuzmins said the company is making progress, but he did not offer a timeline for full recovery. For the two-thirds of customers still locked out, patience is wearing thin. The ransomware recovery process is notoriously slow, especially when attackers have had weeks of unfettered access to the network.

The key lesson here is painfully simple: unpatched systems are an open door. LVM’s two-year-old vulnerability was all the invitation the attackers needed.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version