Latvian Police Arrest Suspected Hacker in Extortion Scheme Targeting Local Businesses
Latvian authorities have arrested a 23-year-old man in connection with cyberattacks against at least two companies, including electronics repair firm **TSC**. The suspect is accused of exploiting website vulnerabilities to steal personal data and then attempting to extort payments to prevent public disclosure.
Latvian police have announced the arrest of a 23-year-old individual suspected of orchestrating cyberattacks against multiple businesses, culminating in data theft and attempted extortion.
The first incident was detected in February, followed by a second in early September, targeting **TSC**, an electronics repair company that is part of the Latvian telecommunications group **LMT**.
Investigators believe the suspect leveraged automated hacking tools to scan websites for security weaknesses, rather than specifically targeting individual companies. Once vulnerabilities were identified, he allegedly gained unauthorized access to databases, extracting sensitive personal information.
Following the data exfiltration, the suspect reportedly contacted the affected companies via anonymous email accounts, demanding payment to prevent the disclosure of the stolen data.
During a search of the suspect's home in Riga, police uncovered evidence suggesting potential attacks against other businesses, both within Latvia and internationally. These incidents remain under active investigation.
The arrested individual, whose identity has not been publicly disclosed, was apprehended on September 15. He has been formally identified as a suspect in both cases and could face a prison sentence of up to five years.
According to investigators, there is currently no indication that the stolen personal information has been shared with third parties.
**TSC** disclosed its breach earlier this month, confirming that unidentified attackers exploited a vulnerability in its website to access a database containing customer repair requests. The compromised information potentially included customers' names, contact details, device passcodes, bank account numbers, addresses, and building access codes. The specific data varied based on what individual customers had provided.
**TSC**, which operates in Latvia, Lithuania, and Estonia, repairs smartphones, smart devices, and household appliances. The company has not yet disclosed the number of affected customers or the specific vulnerability exploited in the attack.
**TSC** has clarified that its IT systems operate independently from other **LMT** group companies, and the breach did not impact them. There is no evidence suggesting that **LMT**'s core telecommunications network was compromised.