Lithuania suspects foreign intelligence behind theft of 600,000 state records
Lithuania’s government is in damage control mode after discovering that more than 600,000 entries from national data registers were stolen, with prosecutors saying a foreign country is suspected of orchestrating the breach.
The theft targeted the Real Estate Register and the Register of Legal Entities. Attackers got in using login credentials that belonged to institutions authorized to access the data, according to Lithuania’s Prosecutor General’s Office. The stolen records include personal identification numbers tied to property ownership.
Adrijus Jusas, head of the State Enterprise Centre of Registers since June 2023, resigned on Monday. “Given the sensitivity of the situation, I have decided to step down and hand over responsibility to other professionals,” he said in a statement.
Before stepping down, Jusas told BNS that bringing the register systems up to current standards would require somewhere between EUR 50 million and EUR 60 million over three years. He said the Centre had repeatedly asked multiple ministries and government officials for the funding. Nobody approved it.
The breach was first flagged on Friday, May 22, when prosecutors opened a pre-trial investigation. By Monday, the scale became clearer: logins and system access attempts appeared to originate from abroad, routed through systems administered by other Lithuanian institutions.
Lithuania’s Criminal Police Bureau is handling the investigation. The National Cyber Security Centre and the Defence Ministry are now consulting on additional protective measures.
Authorities have already blocked accounts of suspected compromised data users and forced credential resets across affected systems.
Opposition politician Laurynas Kasčiūnas publicly stated on Sunday that the theft is suspected to be a Russian intelligence operation, though he offered no specific evidence. Lithuania, population 2.9 million, has been one of the primary targets of Russia’s hybrid warfare campaign against Europe, which includes sabotage, arson, influence operations, and cyberattacks.
The concern is not abstract. Kasčiūnas warned that the stolen data could include addresses of intelligence officers, military personnel, diplomats, and politicians. That kind of information in the wrong hands enables surveillance, blackmail, and targeted pressure campaigns.
Jusas said no phone numbers, email addresses, bank account details, or payment information were exposed. The data was limited to real estate register extracts and associated personal identification numbers. That’s cold comfort when the breach appears designed for intelligence gathering rather than financial fraud.
The funding angle is worth paying attention to. Legacy government IT systems across the Baltics and Eastern Europe are chronically underfunded, and this is what it looks like when that debt comes due. Lithuania’s Centre of Registers asked for the money to fix its infrastructure, was told no for several years running, and ended up with 600,000 citizen records in someone else’s hands.
Sources: AP News, LRT English, Greenwich Time / AP, Winnipeg Free Press / AP