Daylila

Cybersecurity · Saturday, 22 August 2026

01 · Briefing · what happened

Latvia lost records on 1.2 million people. No passwords were taken, and that is the problem.

Cybersecurity 6 min 27 sources

A road agency in a country of 1.8 million lost 18 years of payment receipts. Poland is checking a health breach that may reach 19 million. What leaked in both is the stuff nobody can change.

1.2m

people in Latvia's leak

out of a population of 1.8 million

2008

oldest receipts taken

18 years of records sitting in one store

3.7m

people in the CareCloud breach

revised up from around 350,000

19m

people Poland is checking

health software firm MyDr, still under investigation

At a glance

  • Latvia's road traffic agency lost data on 1.2 million people, about two-thirds of the country, plus 200,000 businesses.
  • The records were payment receipts going back to 2008: identification numbers, addresses, licence plates, amounts and dates.
  • No passwords were taken, which sounds better than it is, because none of what leaked can be changed.
  • Poland is investigating a health-software breach that may reach 19 million people and 12,000 medical facilities.
  • The US firm CareCloud raised its March breach count tenfold, from around 350,000 people to 3.7 million.
  • Microsoft patched a login-service flaw rated 10 out of 10 that was already in use, and fixed it centrally, so no customer had to act.
  • CISA added five actively exploited flaws to its must-fix list this week, and each of those needs someone at every affected organisation to move.
  • Poisoned Rust code libraries ran malware while software was being built, and were pulled within about 90 minutes.

Forces in play

Records nobody can change High

Latvia, Poland and CareCloud all lost identification numbers, addresses and birth dates. Unlike a password, none of those can be reissued.

Fixes needing many hands Building

Five actively exploited flaws went on CISA's must-fix list, and 300,000 WordPress sites wait on one plugin update. Each needs a separate person to act.

Fixes done centrally Easing

Microsoft's 10-out-of-10 Entra ID login flaw was repaired on Microsoft's own machines, so no customer had to do anything at all.

Someone answering for it Building

Latvian officials resigned over the CSDD loss, Poland swapped its health-network certificates as a precaution, and 17 Iranians were charged over a campaign begun in 2013.

In play CSDD, Latvia's road agency — lost 18 years of payment receipts covering two-thirds of the country MyDr — Polish health software firm at the centre of a breach that may reach 19 million people CareCloud — US health billing firm; revised its March breach from 350,000 to 3.7 million people CISA — the US cyber-defence agency; put five actively exploited flaws on its must-fix list this week Microsoft — fixed a 10-out-of-10 login flaw centrally, and finally deleted a legacy tool attackers relied on

How it unfolded

  1. 2008 the oldest of the payment receipts later taken from Latvia's road agency
  2. March attackers spend six days inside CareCloud's cloud environment
  3. Tue CISA adds four actively exploited flaws; Latvia confirms 1.2 million people affected
  4. Thu a Rust developer's account is used to poison three widely used code libraries
  5. Fri Poland says it is replacing its health-network certificates; Apollo confirms its own breach

Where this points

Watch whether Poland's 19 million figure holds once its investigation closes, and whether any of these agencies say what they will now stop keeping.

Full briefing

Latvia lost the facts you cannot change

Latvia’s road traffic agency, CSDD, says hackers took data on more than 1.2 million people and 200,000 businesses [1]. Latvia has just over 1.8 million residents. The agency registers vehicles and issues driving licences, so the stolen set covers about two-thirds of the country [1].

The records came from payment receipts going back to 2008 [1]. They hold personal identification numbers, licence plates, payment amounts and dates, and the addresses printed on vehicle registration certificates [1]. Phone numbers, email addresses, usernames and passwords were not taken [1]. Senior officials resigned over it [1]. CERT.LV, Latvia’s national cyber-response team, warned that criminals will use the data to build convincing approaches to victims [1].

Poland is investigating a larger one. Health software firm MyDr may have exposed data on nearly 19 million people and more than 12,000 medical facilities [2]. As a precaution, Poland’s e-Health Centre is replacing the digital certificates that let medical systems connect to P1, the national prescriptions platform [2]. There is no evidence yet that those certificates were stolen [2].

In the United States, CareCloud raised its count for a March break-in from around 350,000 people to 3,756,469 [3][4]. Attackers were inside one of its cloud environments from 10 to 16 March [3]. The stolen data includes names, addresses, Social Security numbers, driving licence numbers, dates of birth, health insurance details and medical records [3]. Most of those people have never heard of CareCloud, because it sells software to their doctors, not to them [4].

Toronto’s Hospital for Sick Children said staff and job applicants had data exposed through a flaw in software it buys in [5][6]. Clinical systems and patient records were untouched [5]. It is the hospital’s second known incident since the 2022 ransomware attack that took weeks to recover from [6].

Why “change your password” has nothing to hold on to

Notice what did not leak in Latvia. No passwords [1]. That sounds like the good news. It is closer to the opposite.

A password is replaceable. An identification number is not. Neither is a date of birth, an address history, a licence plate or the number on a driving licence. Those are exactly the facts that leaked in Latvia, in Poland and at CareCloud [1][2][3]. They are also the facts a bank, a clinic or a phone company asks for when it wants to check that you are you.

So if you are in one of these, the useful move is not a password change. Expect a caller who already knows your details, and hang up and dial the number you already had. Lock or freeze your credit file if your country offers it. And treat a message that opens by proving it knows you as less trustworthy, not more.

Two flaws rated 10 out of 10, and the question of who has to act

Microsoft patched a flaw in Entra ID, its cloud login service, rated 10.0 on the standard zero-to-ten severity scale [7]. It was already being used in attacks [7][8]. Microsoft says no customer action is required, because the fix landed on Microsoft’s own machines [7]. Entra ID was formerly called Azure Active Directory, and it is what signs staff in to Microsoft accounts across a very large share of companies [8].

Set that beside the rest of the week. CISA, the US cyber-defence agency, added four actively exploited flaws to its must-fix list on Tuesday, in Microsoft’s key exchange service, SharePoint, VMware vCenter and Apple’s macOS [9]. It added a Zimbra mail flaw on Friday [10]. Citrix patched a critical login bypass in NetScaler that a remote attacker can use with no password and no help from a user [11]. Around 300,000 WordPress sites run a form plugin whose flaw lets a stranger upload a program and run it [12]. CISA separately ordered federal agencies to patch TrueConf servers already under attack [13].

Every one of those needs somebody, somewhere, to go and do it. The severity number describes the flaw. It says nothing about how many separate hands have to move.

That gap is being worked. CISA and the FBI say the Medusa ransomware crew has now hit more than 500 organisations, and has been seen using newly announced flaws within 24 hours of disclosure [14].

Poisoned code, pulled in about ninety minutes

Someone got into the account of a Rust developer and published booby-trapped versions of three of their code libraries [15][16]. One of them, arrayref, was downloaded more than 53 million times in the past 90 days [15]. The poisoned versions added a dependency whose name sat one character away from a real one [15]. Its setup script ran while a program was being built, before anyone had run the finished software [16].

The bad releases were removed within 86 to 107 minutes [16]. Researchers at Wiz have tied the campaign to North Korean state hackers [17]. Separately, Trend Micro found 14 packages on npm posing as calendar tools that quietly launch a Linux implant when a project imports them [18].

If you write software, the plain step is to pin arrayref at 0.3.9 or earlier and check your build cache [16].

Stolen logins, still the main road in

A seller calling themselves TheHatman is advertising 3.64 million employee records for sale [21]. They are claimed to come from the Microsoft cloud accounts of McDonald’s, Vodafone, Gap, Tata Consultancy Services and others [21]. The route in was stolen logins, not any flaw [21]. Apollo Global Management confirmed that intruders reached some of its cloud platforms between 6 and 10 July [22]. It was part of a run of attacks on financial firms that began with phone calls [22].

Researchers also examined a ready-made toolkit, sold for about $10,000, that builds convincing fake login pages [19][20]. Its seller claims it can register the attacker’s own passkey on an account it has already taken over [20]. A passkey is the strong login meant to replace passwords. If the claim holds, resetting the password would not evict the intruder [19]. Google is separately tracking three suspected Russian spying groups that now abuse legitimate sign-in permission screens, which makes the approach look genuine to the target [27].

Consequences, and one quiet deletion

The US Justice Department unsealed charges against 17 Iranians tied to the Mabna Institute [23]. It alleges a campaign running from 2013 that hit 144 American universities and took 31 terabytes of academic work [23]. Berlin cut two state ministries off the city government network after a breach, leaving staff on telephone and fax, with some housing benefit applications unprocessable [24]. Australia’s corporate regulator says people lost $7.4m to investment scams using deepfakes of public figures, with the prime minister the most-copied face [25].

And Microsoft has finally deleted WMIC, a built-in Windows command tool it first marked for removal back in 2016 [26]. Attackers liked it because it was already installed and already signed by Microsoft [26]. Ten years to take away one tool is the honest pace of this work.

02 · Lesson · why it matters

The proof runs out for everyone, not just the people in the leak

A fact identifies you only while almost nobody else knows it. Leak it widely enough and it stops proving anything, about anyone.

How it works

  1. A fact identifies you because few people know it
  2. Organisations use it to check that you are you
  3. A leak hands that fact to everyone at once
  4. Now the same check passes for the impostor
  5. And it stops working for people who were never in the leak

The twist

The leak does not only harm the people in it. It retires the question for everybody, because a bank asking your date of birth was only ever betting that almost nobody else could answer.

Where you've seen this

Bank security questions

your mother's maiden name stopped proving anything once it sat in a hundred leaked databases

Paper identity documents

a document proves little once the details it carries are sold in bulk

Qualifications

a certificate sorts people only while it stays rare; when everyone holds one, employers start looking for something else

The catch

Some proofs survive it. A code sent to the phone already on file still works, because it tests something you hold now rather than something you once told someone.

Full lesson

The line everyone skipped

Latvia’s road traffic agency lost data on 1.2 million people. In its statement it added, almost as reassurance, that no usernames or passwords were taken.

Read that again. What was taken instead were identification numbers, addresses, licence plates and dates of payment. The passwords are the only things on that list anyone could have changed.

What a check is actually asking

When a bank asks for your date of birth, it is not testing your memory. It is making a bet.

The bet is that of everyone who might ring that number today, almost nobody else could answer. That is the whole mechanism. A fact works as proof in exact proportion to how few people hold it.

So the strength of a check is not a property of the fact. It is a property of how rare the fact is right now, somewhere out in the world, in places the bank cannot see.

Why the arithmetic collapses at scale

Latvia has 1.8 million residents. The leak covers 1.2 million of them.

Before this week, an identification number narrowed a caller down to one person in the country. Now, for whoever holds the file, it narrows nothing. The same string of digits is on one side of a transaction and on the other. Ask for it and you have learned that the caller can read.

Poland is checking a health-software breach that may reach 19 million people. The US firm CareCloud revised one March break-in from 350,000 people to 3.7 million, and what it lost included Social Security numbers, driving licence numbers and dates of birth. These are not stories about privacy in the ordinary sense. They are stories about the country’s stock of usable proof being spent.

The people who were never in it

Here is the part that does not fit the usual telling.

Suppose you were careful. Suppose you never registered a car in Latvia, never used a Polish clinic, never heard of CareCloud. Your date of birth is still worth less as proof this week than it was last week. So is your address, and your mother’s maiden name, and the last four digits of your card.

Nothing happened to you. Your proof was devalued by other people’s leaks, because it was never yours alone. It was a shared instrument, and the value of a shared instrument is set by how many copies of it are loose. You are not standing outside the system watching it fail. You are inside it, holding the same worn coins as everyone else.

The arrangement underneath

None of this had to be built this way, and no one announced the choice.

Somebody decided that a number printed on a form would serve as proof of identity. It was cheap and it was convenient, and it worked well enough for long enough that it came to look like a fact of nature rather than a decision. It was always a decision, and it always had a shelf life.

Somebody also decided that a road agency should keep payment receipts for eighteen years. Probably nobody decided it in a meeting. There was no rule saying delete, so the receipts stayed, quietly turning from paperwork into a target. The purpose was registering cars. The damage came entirely from the residue.

What still holds

A few checks survive all of this, and they share a shape.

Poland’s response was to replace the certificates its medical systems use, before anyone had misused them. A code sent to the phone already on file works for the same reason. Both test something held right now, not something once told to somebody and written down. What you have keeps working when what you know does not.

That is the honest boundary. You can be careful with your own details and still lose their value, because the leak that spends them belongs to someone else, somewhere you cannot see. Nobody can count how much of themselves is already loose in the world. That is a good reason to hold any conclusion about your own safety a little more loosely too.

03 · Lab · your turn

The verification desk

Rehearse deciding what counts as proof of identity, and watch leaked facts stop proving anything.

04 · Hope · carry this

Poland changed the keys to its health network before anyone had misused them, and Latvia's officials answered for the loss with their jobs. Neither undoes a leak; both are a habit still setting in.

Across the beats