Geopolitical Context

Latvia's cybersecurity posture reflects broader regional tensions stemming from Russia's 2022 invasion of Ukraine. CERT.LV's Q2 2026 report indicates that while cyber incident volumes have moderated from peak levels, they remain significantly elevated compared to pre-2022 baselines—with manually processed incidents sixfold higher and compromised devices eightfold higher than before the invasion. The report explicitly identifies Russia as "the main source of cyber threats to Latvia," attributing activity to Russia-backed cyber actors and hacktivists, some of which appears responsive to Latvia's public support for Ukraine. This pattern is consistent with observed Russian cyber operations targeting NATO's eastern flank states that have provided material or political backing to Kyiv. The sustained threat environment has driven institutional adaptation, including expanded SOC coverage, DNS firewall deployment blocking over 5 million malicious access attempts in H1 2026, and mandatory endpoint visibility regulations—reflecting a shift toward persistent, state-backed threat modeling rather than episodic incident response.

State Actor Alignment

The report directly attributes the elevated threat environment to Russia, stating that "Russia remains the main source of cyber threats to Latvia" and that "activities of Russia-backed cyber attackers and hacktivists, including in response to Latvia's expressed support for Ukraine, are likely to continue." This framing is consistent with Latvia's NATO membership and its position as a frontline state in the Alliance's eastern flank. Latvia has been subject to EU sanctions coordination against Russia since 2022 and has provided political, humanitarian, and military support to Ukraine. The cyber threat landscape described aligns with documented Russian cyber operations against Baltic states and other NATO members supporting Ukraine, including DDoS campaigns, ransomware deployment, and information operations. The report does not specify particular Russian state entities (e.g., GRU, SVR, FSB) or named threat groups, maintaining attribution at the state-sponsorship level rather than tactical actor identification.

Business Impacty pro region

The Latvian case illustrates broader cybersecurity dynamics across the Baltic region and NATO's eastern flank. Estonia, Lithuania, and Poland face similar threat profiles, with elevated cyber activity correlating to their geographic proximity to Russia and vocal support for Ukraine. The sustained high threat level in Latvia—now entering its fifth year since the 2022 invasion—suggests that regional cyber conflict has transitioned from acute crisis to persistent strategic competition. The report's emphasis on vulnerability exploitation, ransomware, and DDoS attacks mirrors threat patterns observed across Central and Eastern Europe, indicating coordinated or at minimum parallel campaigns. Latvia's institutional response, including mandatory SOC deployment and expanded CERT capabilities, may serve as a model for smaller NATO members seeking to enhance resilience under resource constraints. The hosting of the TF-CSIRT meeting in Riga with over 150 European experts signals Latvia's growing role in regional cyber defense coordination, potentially strengthening collective response mechanisms within the EU Cyber Crisis Liaison Organisation Network (CyCLONe) and NATO cyber defense frameworks. The report's note that fraud costs Latvian bank customers approximately €1.3 million monthly also highlights the civilian economic impact of sustained cyber threat environments, a factor relevant to broader European discussions on critical infrastructure protection and digital resilience.

Forecast

If geopolitical tensions surrounding the Russia-Ukraine conflict remain elevated, Latvia is likely to continue experiencing above-baseline cyber threat activity through at least 2027, with Russia-linked actors maintaining focus on Baltic states as symbolic and strategic targets. Should Latvia increase material support to Ukraine or host additional NATO infrastructure, retaliatory DDoS campaigns and hacktivist activity may intensify in the near term. Conversely, if diplomatic de-escalation occurs, a gradual normalization of threat levels may follow, though likely with a lag of several quarters as operational infrastructure and actor motivations adjust. The continued emphasis on vulnerability exploitation and ransomware suggests that Latvian organizations with insufficient patch management or legacy systems will remain high-value targets, particularly in critical infrastructure and government sectors. If CERT.LV's expanded SOC and DNS firewall capabilities continue scaling, detection and mitigation rates may improve, potentially reducing successful compromise rates even if attack volumes remain constant. The growing role of artificial intelligence in both attack and defense, as noted in the report, may accelerate the operational tempo, requiring continuous capability investment to maintain current resilience levels.