
Situation Summary
Latvia remains at composite threat level #135 globally, with no tracked security incidents in the current assessment window. However, the country faces a sustained hybrid-threat environment characterized by irregular migration pressure on the eastern border with Belarus, ongoing Russian sub-conventional activity (cyber, sabotage, intelligence operations, and drone incursions), and critical infrastructure vulnerabilities exposed by recent cyberattacks. The security posture in eastern border regions has tightened in response to these pressures, with government agencies preparing emergency declarations and heightened airspace vigilance.
Key Developments
- Eastern border migrant interdiction (Saturday 2026-08-29, reported Sunday 2026-08-30). Latvia's State Border Guard Service prevented 97 foreign nationals from entering via Belarus, continuing a pattern of sustained irregular migration pressure on the eastern frontier and indicating heightened cross-border enforcement activity.
- Eastern border emergency regime proposal (in force as of 2026-08-27, actively discussed 2026-08-30). Latvia's Ministry of Climate and Energy is pursuing a formal state-of-emergency declaration for eastern border zones, citing cyber threats, sabotage risks, drone/unidentified aerial object sightings, and escalation risks affecting healthcare, energy, and water infrastructure.
- NATO air interception near Rugaī (incident ~one week prior; actively reported 2026-08-30). An Italian Eurofighter shot down a drone that had entered Latvian airspace via Belarus near Rugaī (30 km from the Russian border). Authorities suspect Russian electronic warfare may have degraded the aircraft's navigation, underscoring ongoing airspace-security challenges.
- Russian sub-conventional activity escalation statement (2026-08-30). Latvia's foreign minister publicly stated that Russia has increased hybrid operations short of open warfare, emphasizing that such activity has been continuous, reinforcing the elevated threat perception driving security controls and military presence in border areas.
- CSDD cyberattack notification phase (breach in early August; active user mitigation through 2026-08-30). The Road Traffic Safety Directorate continues notifying 1.2 million individuals and ~200,000 legal entities of a data breach that exposed vehicle information on police, border guard, security service, and military intelligence assets; criminal proceedings for unauthorized access to critical infrastructure remain open.
- Latvian nationals arrested in foreign sabotage plot (arrests earlier this week, reported through 2026-08-29–30). A 26-year-old Latvian suspect was arrested in Hamburg and another detained in Slovakia in connection with a planned attack on a Slovak drone manufacturer, raising counter-extremism and counter-sabotage scrutiny within Latvia.
Highest-Risk Areas
Eastern and southeastern Latvia drive the sub-national risk profile, with Rēzekne (risk 68) and Daugavpils (risk 65) heading the ranking, followed by districts in Rēzeknes, Ludzas, and Balvu novads. These areas are concentrated within 30–100 km of the Belarus and Russian borders, where irregular migration, drone incursions, cyber threats, and hybrid operations intersect. Risk elevation reflects both operational pressure (border enforcement, critical infrastructure vulnerability) and strategic exposure to Russian sub-conventional activity and potential sabotage networks.
How GeoBit Would Assist
Security teams would employ AOI Monitoring & Early Warning to track persistent developments in Rēzekne, Daugavpils, and the eastern border corridor with real-time alerting. Network & Actor Analysis linked to OSINT (Telegram, X, radio SIGINT) would detect emerging hybrid-threat indicators and extremist recruitment patterns. GIS & Spatial Analysis combined with satellite imagery would provide situational awareness of border activity, critical infrastructure status, and airspace incidents, enabling duty-of-care teams to anticipate service disruptions and route personnel safely.
7-Day Outlook
Eastern border pressure from irregular migration and hybrid operations will likely persist at current intensity over the next week, with formal emergency declarations possible in critical-infrastructure zones. Cyber-incident response and criminal investigations will remain active, potentially triggering additional data disclosures or security advisories. No imminent escalation beyond the hybrid-threat threshold is signaled, but heightened enforcement and military visibility should be expected in border-adjacent regions.
Highest-Risk Areas — Ranked
| # | State / Region | Risk |
|---|---|---|
| 1 | Rēzekne | 68 |
| 2 | Daugavpils | 65 |
| 3 | Rēzeknes novads | 58 |
| 4 | Ludzas novads | 55 |
| 5 | Balvu novads | 52 |
| 6 | Preiļu novads | 50 |
| 7 | Krāslavas novads | 48 |
| 8 | Jēkabpils novads | 47 |
| 9 | Augšdaugavas novads | 46 |
| 10 | Aizkraukles novads | 45 |
| 11 | Varakļānu novads | 44 |
| 12 | Līvānu novads | 43 |
Sources
Previous Daily Briefs
A new Latvia brief is written every day — each with its own risk map and downloadable CSV. Here's the last week; use the calendar to go further back.
- August 28, 2026
- August 26, 2026
- August 24, 2026
- August 22, 2026
- August 20, 2026
- August 17, 2026
- August 15, 2026
📅 Browse every day by calendar →
Highlighted days have a brief. Tap a day for that day's map & analysis, or “csv” for that day's dataset ($5).
Atlas — our AI intelligence desk — emails them this snapshot personally. Nothing else, no list.