What Happened
On September 15, 2026, Latvia's State Police arrested a 23-year-old man in Riga on suspicion of hacking at least two companies, stealing personal data, and attempting to extort the victims for money. The arrest followed an investigation by the Cybercrime Combating Department's First Division, which linked two separate criminal cases to the same suspect and formally identified him as a person of interest in both.
The most recent and highest-profile target was TSC, an electronics and household-appliance repair company that is part of Latvian telecommunications group LMT. Police say TSC was breached in early September 2026 using methods similar to an earlier attack detected in February against a different, unnamed Latvian company.
How the Scheme Worked
According to State Police, the suspect did not deliberately target specific businesses. Instead, he allegedly ran automated tools that scanned company websites and other public-facing infrastructure for exploitable vulnerabilities, then used whatever access he found to pull data out of backend databases. He is also accused of using virtual masking tools, such as VPNs or proxy services, to obscure his real location and identity while carrying out the intrusions.
Once inside a target's systems, the suspect allegedly exported personal information stored in the database and then contacted the affected company through anonymous email accounts, demanding payment in exchange for not leaking the stolen data. Neither the exact ransom amount nor a specific deadline has been disclosed publicly.
TSC has not said how many customers were affected or which vulnerability was exploited, but police confirmed the data pulled from the company's systems included customer names, contact details, device passcodes, bank account numbers, home addresses, and building access codes — a combination that would let a criminal go well beyond simple spam or phishing toward targeted burglary or fraud. Investigators say that, based on evidence gathered so far, the stolen data does not appear to have been passed on to third parties.
Investigation and Charges
The case was worked by the First Division of the State Police's Cybercrime Combating Department, with support from LMT's internal security service and CERT.LV, Latvia's national computer emergency response team. During the September 15 arrest, officers also searched an address in Riga and seized additional evidence, which reportedly turned up signs of further attacks against other companies in Latvia and abroad — those leads remain under investigation.
The suspect faces charges under three sections of Latvia's Criminal Law: Section 241, Paragraph 2 (unauthorized access to an automated data processing system for financial gain), Section 183, Paragraph 1 (extortion), and Section 243, Paragraph 3 (disrupting the operation of an automated data processing system and unlawfully handling the information it contains, also for financial gain). Latvian authorities say a conviction on the most serious of these counts could carry up to five years in prison. As with any suspect, he is presumed innocent unless and until convicted.
Broader Context
The case fits a pattern regulators and researchers have flagged repeatedly this year: attackers increasingly favor opportunistic, automated scanning over bespoke campaigns against large enterprises, because mid-size companies — repair shops, retailers, service providers — often run outdated or misconfigured web applications and lack dedicated security teams to catch an intrusion quickly. Extortion by anonymous email, without ever deploying ransomware, has become a low-cost, low-skill way to monetize a breach once data has been exfiltrated.
It's also a data point for Baltic cybercrime policing specifically. Latvia's State Police, CERT.LV, and private-sector security teams like LMT's have increasingly worked joint cases together, and Latvian authorities have been active in cross-border cybercrime enforcement this year. Whether this suspect's other alleged targets, described only as "domestic and international businesses," surface publicly will depend on how the wider investigation develops.