Cybersecurity · Saturday, 22 August 2026
01 · Briefing · what happened
Latvia lost records on 1.2 million people. No passwords were taken, and that is the problem.
A road agency in a country of 1.8 million lost 18 years of payment receipts. Poland is checking a health breach that may reach 19 million. What leaked in both is the stuff nobody can change.
1.2m
people in Latvia's leak
out of a population of 1.8 million
2008
oldest receipts taken
18 years of records sitting in one store
3.7m
people in the CareCloud breach
revised up from around 350,000
19m
people Poland is checking
health software firm MyDr, still under investigation
At a glance
- Latvia's road traffic agency lost data on 1.2 million people, about two-thirds of the country, plus 200,000 businesses.
- The records were payment receipts going back to 2008: identification numbers, addresses, licence plates, amounts and dates.
- No passwords were taken, which sounds better than it is, because none of what leaked can be changed.
- Poland is investigating a health-software breach that may reach 19 million people and 12,000 medical facilities.
- The US firm CareCloud raised its March breach count tenfold, from around 350,000 people to 3.7 million.
- Microsoft patched a login-service flaw rated 10 out of 10 that was already in use, and fixed it centrally, so no customer had to act.
- CISA added five actively exploited flaws to its must-fix list this week, and each of those needs someone at every affected organisation to move.
- Poisoned Rust code libraries ran malware while software was being built, and were pulled within about 90 minutes.
Forces in play
Latvia, Poland and CareCloud all lost identification numbers, addresses and birth dates. Unlike a password, none of those can be reissued.
Five actively exploited flaws went on CISA's must-fix list, and 300,000 WordPress sites wait on one plugin update. Each needs a separate person to act.
Microsoft's 10-out-of-10 Entra ID login flaw was repaired on Microsoft's own machines, so no customer had to do anything at all.
Latvian officials resigned over the CSDD loss, Poland swapped its health-network certificates as a precaution, and 17 Iranians were charged over a campaign begun in 2013.
How it unfolded
- 2008 the oldest of the payment receipts later taken from Latvia's road agency
- March attackers spend six days inside CareCloud's cloud environment
- Tue CISA adds four actively exploited flaws; Latvia confirms 1.2 million people affected
- Thu a Rust developer's account is used to poison three widely used code libraries
- Fri Poland says it is replacing its health-network certificates; Apollo confirms its own breach
Where this points
Watch whether Poland's 19 million figure holds once its investigation closes, and whether any of these agencies say what they will now stop keeping.
Full briefing
Latvia lost the facts you cannot change
Latvia’s road traffic agency, CSDD, says hackers took data on more than 1.2 million people and 200,000 businesses
The records came from payment receipts going back to 2008
Poland is investigating a larger one. Health software firm MyDr may have exposed data on nearly 19 million people and more than 12,000 medical facilities
In the United States, CareCloud raised its count for a March break-in from around 350,000 people to 3,756,469
Toronto’s Hospital for Sick Children said staff and job applicants had data exposed through a flaw in software it buys in
Why “change your password” has nothing to hold on to
Notice what did not leak in Latvia. No passwords
A password is replaceable. An identification number is not. Neither is a date of birth, an address history, a licence plate or the number on a driving licence. Those are exactly the facts that leaked in Latvia, in Poland and at CareCloud
So if you are in one of these, the useful move is not a password change. Expect a caller who already knows your details, and hang up and dial the number you already had. Lock or freeze your credit file if your country offers it. And treat a message that opens by proving it knows you as less trustworthy, not more.
Two flaws rated 10 out of 10, and the question of who has to act
Microsoft patched a flaw in Entra ID, its cloud login service, rated 10.0 on the standard zero-to-ten severity scale
Set that beside the rest of the week. CISA, the US cyber-defence agency, added four actively exploited flaws to its must-fix list on Tuesday, in Microsoft’s key exchange service, SharePoint, VMware vCenter and Apple’s macOS
Every one of those needs somebody, somewhere, to go and do it. The severity number describes the flaw. It says nothing about how many separate hands have to move.
That gap is being worked. CISA and the FBI say the Medusa ransomware crew has now hit more than 500 organisations, and has been seen using newly announced flaws within 24 hours of disclosure
Poisoned code, pulled in about ninety minutes
Someone got into the account of a Rust developer and published booby-trapped versions of three of their code libraries
The bad releases were removed within 86 to 107 minutes
If you write software, the plain step is to pin arrayref at 0.3.9 or earlier and check your build cache
Stolen logins, still the main road in
A seller calling themselves TheHatman is advertising 3.64 million employee records for sale
Researchers also examined a ready-made toolkit, sold for about $10,000, that builds convincing fake login pages
Consequences, and one quiet deletion
The US Justice Department unsealed charges against 17 Iranians tied to the Mabna Institute
And Microsoft has finally deleted WMIC, a built-in Windows command tool it first marked for removal back in 2016
02 · Lesson · why it matters
The proof runs out for everyone, not just the people in the leak
A fact identifies you only while almost nobody else knows it. Leak it widely enough and it stops proving anything, about anyone.
How it works
- A fact identifies you because few people know it
- Organisations use it to check that you are you
- A leak hands that fact to everyone at once
- Now the same check passes for the impostor
- And it stops working for people who were never in the leak
The twist
The leak does not only harm the people in it. It retires the question for everybody, because a bank asking your date of birth was only ever betting that almost nobody else could answer.
Where you've seen this
Bank security questions
your mother's maiden name stopped proving anything once it sat in a hundred leaked databases
Paper identity documents
a document proves little once the details it carries are sold in bulk
Qualifications
a certificate sorts people only while it stays rare; when everyone holds one, employers start looking for something else
The catch
Some proofs survive it. A code sent to the phone already on file still works, because it tests something you hold now rather than something you once told someone.
Full lesson
The line everyone skipped
Latvia’s road traffic agency lost data on 1.2 million people. In its statement it added, almost as reassurance, that no usernames or passwords were taken.
Read that again. What was taken instead were identification numbers, addresses, licence plates and dates of payment. The passwords are the only things on that list anyone could have changed.
What a check is actually asking
When a bank asks for your date of birth, it is not testing your memory. It is making a bet.
The bet is that of everyone who might ring that number today, almost nobody else could answer. That is the whole mechanism. A fact works as proof in exact proportion to how few people hold it.
So the strength of a check is not a property of the fact. It is a property of how rare the fact is right now, somewhere out in the world, in places the bank cannot see.
Why the arithmetic collapses at scale
Latvia has 1.8 million residents. The leak covers 1.2 million of them.
Before this week, an identification number narrowed a caller down to one person in the country. Now, for whoever holds the file, it narrows nothing. The same string of digits is on one side of a transaction and on the other. Ask for it and you have learned that the caller can read.
Poland is checking a health-software breach that may reach 19 million people. The US firm CareCloud revised one March break-in from 350,000 people to 3.7 million, and what it lost included Social Security numbers, driving licence numbers and dates of birth. These are not stories about privacy in the ordinary sense. They are stories about the country’s stock of usable proof being spent.
The people who were never in it
Here is the part that does not fit the usual telling.
Suppose you were careful. Suppose you never registered a car in Latvia, never used a Polish clinic, never heard of CareCloud. Your date of birth is still worth less as proof this week than it was last week. So is your address, and your mother’s maiden name, and the last four digits of your card.
Nothing happened to you. Your proof was devalued by other people’s leaks, because it was never yours alone. It was a shared instrument, and the value of a shared instrument is set by how many copies of it are loose. You are not standing outside the system watching it fail. You are inside it, holding the same worn coins as everyone else.
The arrangement underneath
None of this had to be built this way, and no one announced the choice.
Somebody decided that a number printed on a form would serve as proof of identity. It was cheap and it was convenient, and it worked well enough for long enough that it came to look like a fact of nature rather than a decision. It was always a decision, and it always had a shelf life.
Somebody also decided that a road agency should keep payment receipts for eighteen years. Probably nobody decided it in a meeting. There was no rule saying delete, so the receipts stayed, quietly turning from paperwork into a target. The purpose was registering cars. The damage came entirely from the residue.
What still holds
A few checks survive all of this, and they share a shape.
Poland’s response was to replace the certificates its medical systems use, before anyone had misused them. A code sent to the phone already on file works for the same reason. Both test something held right now, not something once told to somebody and written down. What you have keeps working when what you know does not.
That is the honest boundary. You can be careful with your own details and still lose their value, because the leak that spends them belongs to someone else, somewhere you cannot see. Nobody can count how much of themselves is already loose in the world. That is a good reason to hold any conclusion about your own safety a little more loosely too.
03 · Lab · your turn
The verification desk
Rehearse deciding what counts as proof of identity, and watch leaked facts stop proving anything.
04 · Hope · carry this
Poland changed the keys to its health network before anyone had misused them, and Latvia's officials answered for the loss with their jobs. Neither undoes a leak; both are a habit still setting in.
More from Cybersecurity