Lithuania Probes Foreign Hand in Leak of 600,000-Plus National Register Records

Lithuanian authorities suspect state-linked actors after a data breach exposed more than 600,000 entries from government population and registration databases.

ThreatVectr Newsdesk· 2 min read
Lithuania Probes Foreign Hand in Leak of 600,000-Plus National Register Records
Share

Vilnius, Lithuania — Lithuanian authorities are investigating a data breach that exposed more than 600,000 entries from the country's national civil registers, with officials saying foreign involvement is suspected.

The State Data Protection Inspectorate of Lithuania confirmed the incident and said the compromised records originated from national registration databases maintained by government agencies. The exact categories of exposed data — which may include names, identification numbers, addresses, and civil status information — have not been fully disclosed while the investigation continues.

The scope is significant. Six hundred thousand records represents roughly one-fifth of Lithuania's total population of about 2.8 million.

Lithuanian officials said (without naming a specific actor) that they believe a foreign state or foreign-linked party played a role in extracting the data. The country has previously attributed cyberattacks to groups operating out of Russia and Belarus, and it sits on the eastern flank of NATO, making it a routine target for influence and intelligence operations.

No ransomware group has claimed the incident publicly, and Lithuanian authorities have not characterized it as a ransomware event. The breach appears focused on data collection rather than extortion — a pattern consistent with espionage-oriented operations.

But the method of exfiltration remains undisclosed. Authorities have not confirmed whether the attacker exploited a software vulnerability, used compromised credentials, or abused an insider access point (a detail that will likely shape any resulting regulatory response under the EU's General Data Protection Regulation).

The State Data Protection Inspectorate is the lead supervisory authority under GDPR in Lithuania and carries authority to issue fines of up to 4 percent of annual global turnover against public bodies that fail to protect personal data. That framing applies even when the victim is a government institution.

Lithuania's National Cyber Security Centre, which sits under the Ministry of National Defence, has been notified and is assisting. The centre publishes an annual threat report that has consistently flagged Russian intelligence services — specifically APT28 and Sandworm — as active against Lithuanian government infrastructure.

No arrests have been announced. The investigation is ongoing.

© 2026 Threat Vectr