This conclusion was reached by the cyber incident prevention organization "Cert.lv" after analyzing the incident. This is the second largest data leak in the history of Latvia. The breach occurred using the Road Traffic Safety Directorate's "Medical" platform, which is used by about 200 doctors to enter medical certificates for drivers. "By exploiting several vulnerabilities, the attacker progressively penetrated deeper. The primary reason was this internet-based system, which, as we found out, had not been properly tested for breaches, and there was also a lack of authentication. And then there is what we also call segmentation or risk separation. (...) It is possible that he started sending queries to the database containing payment information and, accordingly, received this information through error messages," said the deputy director of "Cert.lv". Most likely, the hacker unsuccessfully attempted to attack other government systems as well - this is evidenced by the methods used and the timing of the incident, noted "Cert.lv". The Road Traffic Safety Directorate's system was hacked on the night of August 8. The attack was not detected in time because a warning about a large volume of data leakage was not enabled.