CERT.LV activity review Q2 2026
The cybersecurity threat level in Latvia remains high, and the intensity of cyber threats continues to increase over the long term. This is driven by the geopolitical situation, the increasingly widespread exploitation of vulnerabilities and the use of artificial intelligence in cyber attacks, and users’ uncritical reliance on digital tools. These factors require continued systematic cyber risk management and the consistent strengthening of organisations’ comprehensive cyber resilience.
In Q2 2026, 673 manually processed cyber incidents were recorded, which is 20% fewer than in the previous quarter and 5% fewer than in the corresponding period last year. The number of identified compromised devices also decreased to 396 444, which is 48% fewer than in the previous quarter and 14% fewer than a year ago. However, both indicators remain significantly above the 2022–2024 average, indicating that the cybersecurity threat level remains high.
The full version of the report is available here: PDF
Main threats
The main initial compromise methods continue to be the exploitation of vulnerabilities in information systems accessible via public networks and phishing attacks targeting corporate network users. The risk remains elevated for organisations with outdated or insufficiently maintained websites, unpatched content management systems, and their plugins.
Ransomware attacks and data breaches continue to have the most significant impact on organisations. This is demonstrated by the large-scale cyber attack on the IT infrastructure of JSC Latvijas valsts meži (LVM) during the reporting period, where an unremedied vulnerability in a publicly accessible system became the entry point for a broader attack. This case clearly demonstrated that even a single critical vulnerability can significantly affect an organisation’s business continuity, cause system disruptions, create a risk of data breaches, and require critical IT systems to be shut down.
At the same time, the risks posed by social engineering, identity compromise and information-stealing malware are increasing. Denial-of-service, or DDoS cyber attacks remain an effective instrument of geopolitical pressure and a persistent threat.
Fraud remains the quantitatively dominant type of cyber incident and primarily affects residents. Data compiled by the Finance Latvia Association for the first six months of 2026 also show that customers of Latvia’s largest banks lose an average of around EUR 1.3 million to fraud each month. Therefore, alongside technical security measures, it is essential to continue strengthening public awareness and resilience against social engineering attacks, particularly phishing.
Russia remains the main source of cyber threats to Latvia. The activities of Russia-backed cyber attackers and hacktivists, including in response to Latvia's expressed support for Ukraine, are likely to continue.
Given the current nature of the threats, organisations should prioritise strengthening vulnerability management, continuous cybersecurity monitoring (SOC/EDR/XDR/SIEM), the use of multi-factor authentication, backup management, supply chain security, and regular user training, while periodically testing incident response and business continuity plans.
CERT.LV performance results
At the same time, growing threats are driving the development of cybersecurity capabilities. They increase demand for data-driven services to improve the ability to identify and mitigate threats in a timely manner.
In the first six months of 2026, the preventive work of the CERT.LV Cyber Incident Response Team and the active protection provided by the DNS firewall prevented more than 5 million attempts to access malicious websites – 6.5 times more than in the corresponding period last year. A record high of 1.1 million was reached in June.
By improving automated threat detection methods, in Q2 CERT.LV proactively identified and prevented 1166 active fraud campaigns – 900 more than in the previous quarter – before they reached users on a large scale and caused losses.
During the reporting period, 18 IT system security tests were conducted, identifying 31 vulnerabilities, including critical and high-impact vulnerabilities, which were remediated before they could be exploited in cyber attacks.
Organisations’ endpoint-level visibility is increasing through the implementation of CERT.LV Security Operations Centre (SOC) services in accordance with national regulations. Visibility was provided across a total of 57 021 endpoints, enabling threats to be identified and mitigated in a timely manner and resilience to be strengthened systematically.
Continuing cybersecurity training and public education efforts, 8632 participants were trained at 95 events during the reporting period – 34% and 19% more, respectively, than in the corresponding period last year.
Internationally, Latvia’s role in the European cyber incident response team cooperation community was strengthened by the TF-CSIRT meeting in Riga, which brought together more than 150 industry experts. The forum focused on current cyber threats and challenges in Latvia. This is particularly important at a time when cyber incidents are becoming increasingly complex and closer cooperation between organisations and countries is critically important.
To strengthen and improve institutional cooperation and preparedness to respond to large-scale cyber incidents, the Cyber Europe exercise assessed the Latvian transport sector’s ability to respond to complex cybersecurity incidents in a coordinated manner.
The eighth Threat Hunting Operation organised by CERT.LV, with an expanded presence, demonstrates growing operational maturity and reinforces it as an internationally recognised model of civil-military cooperation.
The Latvian-Singaporean joint team’s 1st place finish in the international cyber defence exercise Locked Shields 2026 demonstrates the high professional competence of Latvia’s cybersecurity specialists and their ability to respond effectively to complex cyber incidents. It also strengthens the cooperation model between public administration, the military sector, and technology companies.
Main conclusions
Although the number of cyber incidents and identified compromised devices decreased during the reporting period, the cybersecurity threat level in Latvia remains high, and the threat intensity continues to increase over the long term. The greatest risks to organisations are posed by vulnerabilities that are not remediated in a timely manner, identity compromise and social engineering attacks, which often serve as the starting point for broader incidents.
At the same time, organisations’ endpoint-level visibility continues to increase through the implementation of the CERT.LV SOC, DNS firewall, and other data-driven cybersecurity services, enabling cyber incidents to be prevented, detected, analysed, and contained in a timely manner, or responded to and resolved.
In the future, organisational resilience will increasingly depend on effective cybersecurity risk management, continuous cybersecurity monitoring (SOC/EDR/XDR/SIEM), the use of multi-factor authentication, backup management, supply chain security, and regular user training, while incident response and business continuity plans are tested regularly.








