
Situation Summary
Latvia remains a lower-tier global security concern (composite risk 9; ranked #131 globally), but faces elevated sub-regional threats concentrated in the eastern border zones and carries active state-sponsored sabotage and hybrid-threat indicators. Recent weeks have seen cross-border infiltration attempts, critical-infrastructure cyberattacks, convictions of foreign saboteurs, and airspace incursions attributed to Russian activity. The overall trajectory reflects sustained hostile-state targeting of Latvia's defense industrial base, borders, and digital infrastructure rather than immediate mass-casualty or systemic breakdown risk.
Key Developments
- Border interdiction (21 August): Latvian border guards discovered and interdicted a concealed tunnel approximately 20 metres from the Belarus border near Krāslava, apprehending 28 individuals who had crossed illegally. Indicates active smuggling/trafficking infrastructure on southern frontier.
- Airspace incursion (21 August): NATO Baltic Air Policing intercepted and shot down a foreign unmanned aerial vehicle over the Balvi region (eastern Latvia), with Latvian military attributing the incursion to Russian electromagnetic warfare causing the UAV to drift across the border. First confirmed airspace violation of this reporting cycle.
- Critical-infrastructure cyberattack aftermath (18–24 August disclosure): A cyberattack on Latvia's Road Traffic Safety Directorate (CSDD) overnight 7–8 August compromised personal data on approximately 1.2 million individuals and 200,000 companies. Law enforcement opened criminal proceedings for unauthorized access to critical infrastructure; incident represents the largest known data breach in Latvia this year and signals vulnerability of state systems to sophisticated intrusion.
- Foreign sabotage convictions (21 August): Riga City Court convicted Denis Lukanenko (10 years) and Karina Ivanova (8.5 years) for sabotage operations against PILOT Automotive Labs Europe, an unmanned-vehicles company, conducted on behalf of a Russian security service. Establishes prosecuted pattern of state-directed industrial sabotage on Latvian soil.
- Cross-border sabotage suspects detained (19–21 August): Latvian State Security Service detained three Latvian citizens suspected of organizing the 15 August arson attack on Milrem Robotics (a NATO-partnered defense contractor in Tallinn, Estonia). Detentions indicate foreign-directed sabotage reaching into Latvian territory and involving Latvian nationals as operational enablers.
Highest-Risk Areas
Eastern border regions—particularly Rēzekne (risk 68), Daugavpils (65), Rēzeknes novads (58), and Ludzas novads (55)—dominate the sub-national ranking and reflect Belarus/Russia frontier exposure. These areas show the highest composite threat scores due to convergence of irregular-migrant transit, smuggling infrastructure (evidenced by the 21 August tunnel discovery), and proximity to Russian military concentration and hybrid-threat staging. Secondary risk clusters in Preiļu and Krāslavas novads similarly reflect border-zone vulnerabilities. Western and central regions show markedly lower scores, suggesting threat concentration is geographically bounded to the eastern periphery.
How GeoBit Would Assist
Security teams in Latvia should deploy AOI Monitoring & Early Warning on the high-risk eastern border zones (Rēzekne, Daugavpils, Ludzas) to detect smuggling activity, irregular crossings, and infrastructure breaches in near-real time. Conflict & Military force-structure and Network & Actor Analysis capabilities enable tracking of sabotage networks and foreign operational cells. Cyber & Critical-Infrastructure search and Shodan scanning would identify vulnerabilities in state and defense-industrial systems post-CSDD breach, informing hardening priorities.
7-Day Outlook
No imminent escalation is signalled, but the tempo of sabotage convictions, border interdictions, and airspace intrusions indicates sustained Russian and Belarusian pressure across multiple domains. Defense-industrial companies and critical-infrastructure operators should anticipate continued targeting; border security will likely remain elevated. Broader NATO and EU responses to the Milrem sabotage may influence escalation risk by late August.
Highest-Risk Areas — Ranked
| # | State / Region | Risk |
|---|---|---|
| 1 | Rēzekne | 68 |
| 2 | Daugavpils | 65 |
| 3 | Rēzeknes novads | 58 |
| 4 | Ludzas novads | 55 |
| 5 | Balvu novads | 52 |
| 6 | Preiļu novads | 50 |
| 7 | Krāslavas novads | 48 |
| 8 | Jēkabpils novads | 47 |
| 9 | Augšdaugavas novads | 46 |
| 10 | Aizkraukles novads | 45 |
| 11 | Varakļānu novads | 44 |
| 12 | Līvānu novads | 43 |
Sources
Previous Daily Briefs
A new Latvia brief is written every day — each with its own risk map and downloadable CSV. Here's the last week; use the calendar to go further back.
- August 22, 2026
- August 20, 2026
- August 17, 2026
- August 15, 2026
- August 13, 2026
- August 11, 2026
- August 9, 2026
📅 Browse every day by calendar →
Highlighted days have a brief. Tap a day for that day's map & analysis, or “csv” for that day's dataset ($5).
Atlas — our AI intelligence desk — emails them this snapshot personally. Nothing else, no list.