Home › Intelligence › Brief
BREACH BRIEF 🟠 High Breach

Electronics Repair Firm TSC Breached via Website Vulnerability, Personal Data Stolen and Extortion Attempt

A 23‑year‑old suspect exploited web‑application flaws at TSC, an electronics repair company in the LMT group, to access databases containing customer names, device passcodes, bank details and building access codes. The stolen data was used in an extortion attempt, though no evidence of further dissemination exists. This incident underscores the need for robust vulnerability management and continuous control assurance to protect personal data.

Verisq™ Intelligence · 📅 September 24, 2026 · 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
therecord.media

Electronics Repair Firm TSC Breached via Website Vulnerability, Personal Data Stolen and Extortion Attempt

What Happened – A 23‑year‑old suspect exploited unpatched web‑application flaws on the TSC (electronics repair) website, gaining unauthorized access to customer databases. Personal data—including names, contact details, device passcodes, bank account numbers and building access codes – was extracted and the attacker demanded payment to keep the information private.

Why It Matters for Trust & Control Assurance

  • Highlights the need for continuous vulnerability scanning and timely remediation as a core control‑assurance activity.
  • Demonstrates how documented remediation evidence supports audit readiness across multiple frameworks.
  • Shows the importance of maintaining a defensible incident‑response trail when data exfiltration and extortion occur.

Who Is Affected – Electronics repair service providers and their customers in Latvia, Lithuania and Estonia; the broader telecommunications group (LMT) that owns TSC.

Recommended Actions

  • Perform a full web‑application security assessment and remediate identified flaws.
  • Deploy continuous security‑monitoring tools that capture evidence of vulnerability management for audit purposes.
  • Review and update incident‑response and extortion‑handling procedures, ensuring documentation is audit‑ready.

Source: The Record

Technical Notes – Attackers used automated scanning tools to locate website vulnerabilities (specific flaw not disclosed). Data exfiltrated included personal identifiers and security‑sensitive information. No evidence of further dissemination was found.

Source: The Record

📰 Original Source
https://therecord.media/latvia-hacker-arrest-cyberattack ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →