A data breach in Lithuania involved more than 600,000 records from national registers.
Internal AffairsLithuania
- Omissions
- The MEP did not specify the date of the data breach, which was publicly disclosed by the Lithuanian Prosecutor General's Office on Friday, 22 or 23 May 2026, roughly three weeks before the session.
- The MEP did not mention that the breach was attributed to a foreign state actor, which is a significant contextual element. Lithuanian President Nausėda described it as the work of a hostile state.
- The MEP did not specify that the breach primarily affected the Real Estate Register and the Register of Legal Entities, not all national registers indiscriminately.
- The MEP did not note that the breach was carried out by abusing login credentials issued to authorised institutions (specifically the Migration Department), which is relevant to understanding the nature of the attack.
- Sources
- SecondaryEuronewsThe Lithuanian general prosecutor's office on Friday announced the leak was primarily from registers of real estate and legal entities accessed by a foreign country. The data leak involved more than 600,000 entries from national registers.
- SecondaryThe RecordThe Lithuanian Prosecutor General's Office said Friday that attackers gained unauthorized access to more than 600,000 records managed by the country's State Enterprise Centre of Registers.
- SecondaryLRT (Lithuanian National Radio and Television)The Prosecutor General's Office is investigating the suspected theft of more than 600,000 Real Estate Register records, including personal identification numbers and other sensitive data.