Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday.
The first attack was detected in February, while a second — using similar methods — was discovered in early September at TSC, an electronics repair company belonging to Latvian telecommunications group LMT.
Police said the suspect exploited vulnerabilities in company websites to gain unauthorized access to databases and extract information, including personal data. He then allegedly contacted the companies through anonymous email accounts and demanded payment in exchange for not disclosing the stolen information.
Investigators believe the suspect used automated hacking tools to scan websites and other online resources for security weaknesses rather than targeting specific companies. He also used digital tools to conceal his actual location.
Police said they uncovered evidence of possible attacks against other businesses in Latvia and abroad during a search of the suspect’s home in Riga. Those incidents remain under investigation.
The man, who was arrested on September 15 and whose identity has not been disclosed, has been formally identified as a suspect in both cases and could face up to five years in prison.
According to investigators, the stolen personal information does not appear to have been shared with third parties.
TSC disclosed the breach earlier this month, saying unidentified attackers had exploited a vulnerability in its website to access a database containing customers’ repair requests.
The stolen information potentially included customers’ names, contact details, device passcodes, bank account numbers, addresses and building access codes. The type of information depended on what individual customers had provided.
TSC, which repairs smartphones, smart devices and household appliances, operates in Latvia, Lithuania and Estonia.
The company has not disclosed how many customers were affected nor has it identified the vulnerability exploited in the attack.
TSC said its IT systems operate separately from those of other LMT group companies and that the breach did not affect them. There is no indication that LMT’s telecommunications network was compromised.

Leave a Reply