An investigation by De facto ([LTV](https://www.lsm.lv/raksts/zinas/latvija/17.08.2026-kiberuzbrukums-latvijas-valsts-meziem-parprotot-zimi-uznemums-divus-gadus-nenoversa-ievainojamibu.a659082/)) revealed that the reason for the successful attack on the information systems of Latvijas valsts meži (LVM) was a vulnerability that the company had known about since 2024. However, the software update was never carried out. According to the company, the attacker or group ByteToBreach infiltrated the internal GeoServer system on June 11. Through it, the attacker gradually gained access to other internal resources, and on June 22, the active phase of the attack began — encryption and theft of data. After the hack, the criminal not only published the stolen information but also detailed their actions, mocking the company's level of protection. It turned out that the attack was made possible due to software that had not been updated for at least two years. This vulnerability had already been pointed out by the cyber incident prevention institution Cert.lv, which sent the company a relevant warning. LVM's IT infrastructure and development director Maris Kuzmins admitted that a mistake was made within the company. "We misinterpreted the information and did not realize that the version we were using was vulnerable. We would have preferred a slightly different communication from Cert, but the truth is that the mistake was on our side," he stated. Cert.lv tried to understand why the warning was ignored. According to the deputy head of the institution, Varis Teivans, the most likely reason was the misinterpretation of the mathematical symbol '≥' ("greater than or equal to"), which is used to denote the range of vulnerable software versions. "It is likely that Latvijas valsts meži misinterpreted this symbol and made an erroneous conclusion that their version of the system was not among the vulnerable ones," Teivans explained. In the field of information security, such designation is considered standard, so they did not seek a specific culprit within the company. After the incident, LVM revised its internal procedures for handling such notifications. According to Kuzmins, while previously vulnerability reports were checked on the principle of 'four eyes', now they are analyzed by several specialists at once. As a result of the attack, the criminals stole about 44 gigabytes of internal data. According to Cert.lv, among the published materials were access keys, authentication data, internal correspondence, information about employees, infrastructure elements, and internal documents of the company. After analyzing the leak, specialists were forced to contact several owners of critical infrastructure facilities, as the stolen materials potentially affected their systems. Experts note that the problem was deeper than a single mistake. Unupdated components were used in several of the company's information systems. Despite previously conducted security checks, this vulnerability was not discovered, as separate testing of this software complex was not carried out. The head of the Possible Security group, Kirill Solovyev, emphasizes that an information security audit should be performed by an independent contractor. "You cannot entrust testing to the same team that developed the system — they simply will not see obvious things," noted the expert. After the incident, almost all information systems of Latvijas valsts meži have already been restored, and the company plans to conduct a comprehensive security audit after the IT infrastructure modernization is completed. The cyberattack has once again intensified the discussion about the role of so-called 'white hat hackers' — specialists who help identify vulnerabilities before criminals exploit them. Currently, new regulations for their activities are being discussed in Latvia, but industry representatives already consider the proposed rules excessively strict. The incident also prompted a more extensive review of government information systems. At the request of Prime Minister Andris Kulbergs, all ministries must assess the risks of their IT systems and prepare proposals for strengthening protection. According to Kirill Solovyev, most successful cyberattacks are still made possible by three factors: untimely software updates, lack of complete accounting of used information systems, and human errors. Experts warn that the situation may become even more complicated in the coming years. The development of artificial intelligence significantly accelerates the search for vulnerabilities for both security specialists and criminals. Cert.lv does not rule out that the industry may face a so-called 'vulnerability apocalypse' — a situation where new weaknesses will be discovered faster than developers can release fixes. The story of Latvijas valsts meži serves as a vivid reminder that even a small mistake in processing a security warning can lead to large-scale consequences.