Lyce · Hybrid Watch

hw_4632fbc68e7aac53

Cyber-attacks on Latvian public-sector websites target unified state platforms and ministries.

Due to intensive distributed-denial-of-service (DDoS) attacks that began on 19 August, the Latvian State Radio and Television Centre (LVRTC) blocked tens of thousands of unique attack sources over two days as websites of state institutions including the Cabinet of Ministers experienced slowdowns or partial unavailability. The unified state-platform (TVP) is the backbone for many governmental web-services in Latvia—its disruption touches national administration and public access. The dynamics reflect hybrid-warfare logic: the attackers profiled the platform, tuned the DDoS assault to specific functions, caused service disruption, and likely sought to undermine trust in state institutions while stretching Latvia’s ICT-incident-response resources. According to Latvia’s CERT (Cert.lv), the wave is linked to Latvia’s recent aid package to Ukraine, suggesting motive aligned with Russian-linked hacktivist campaigns in the Baltic region. While no direct public attribution to the Russian Federation was made in the government statement, the pattern of pro-Russian hacktivist groups (such as NoName057(16)) being active in the region supports inclusion of this incident in a hybrid-warfare dataset.

Occurrence
2024-08-20
Publication
2024-08-19T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
LV
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2024-08-19T22:00:00Z

    Due to intensive distributed-denial-of-service (DDoS) attacks that began on 19 August, the Latvian State Radio and Television Centre (LVRTC) blocked tens of thousands of unique attack sources over two days as websites of state institutions including the Cabinet of Ministers experienced slowdowns or partial unavailability. The unified state-platform (TVP) is the backbone for many governmental web-services in Latvia—its disruption touches national administration and public access. The dynamics reflect hybrid-warfare logic: the attackers profiled the platform, tuned the DDoS assault to specific functions, caused service disruption, and likely sought to undermine trust in state institutions while stretching Latvia’s ICT-incident-response resources. According to Latvia’s CERT (Cert.lv), the wave is linked to Latvia’s recent aid package to Ukraine, suggesting motive aligned with Russian-linked hacktivist campaigns in the Baltic region. While no direct public attribution to the Russian Federation was made in the government statement, the pattern of pro-Russian hacktivist groups (such as NoName057(16)) being active in the region supports inclusion of this incident in a hybrid-warfare dataset.