
Situation Summary
Latvia remains a NATO member state with elevated baseline risk (#132 globally) driven primarily by persistent Russian hybrid-threat activity, cross-border criminal operations, and infrastructure vulnerabilities. The country's eastern and southeastern regions—particularly Rēzekne, Daugavpils, and border-adjacent municipalities—face significantly elevated risk (scores 45–68) due to geographic proximity to Belarus and Russia, repeated airspace incursions, and smuggling/infiltration routes. Over the past two weeks, Latvia has experienced drone incursions, border-tunnel interdictions, suspected state-linked sabotage involving defense contractors, and cyberattacks on critical infrastructure; no discrete new incidents have been confirmed for 25–26 August specifically, but operational tempo remains high.
Key Developments
- NATO Air Policing intercept, Balvi region (15 August). NATO Baltic Air Policing forces shot down a foreign unmanned aerial vehicle over Balvi; Latvian military attributed the incursion to Russian operations. The incident underscores persistent airspace violations and Russia's continued use of unmanned systems for reconnaissance and signaling.
- Clandestine tunnel discovered near Belarus border, Krāslava (21 August). Latvian border guards interdicted a concealed tunnel approximately 20 metres from the Belarus border and apprehended suspects. The discovery indicates organized smuggling or infiltration infrastructure targeting critical border zones.
- Sabotage arrests in defense-sector arson, Latvian suspects (19 August, case updated 25 August). Latvian State Security Service detained three Latvian citizens suspected of organizing an 15 August arson attack on Milrem Robotics (an Estonian defense-technology firm). The case suggests possible state-directed or state-coordinated sabotage of NATO-aligned defense industrial capacity.
- Cyberattack on CSDD and data exfiltration (attack 7–8 August, reporting 19–24 August). Latvia's Road Traffic Safety Directorate (CSDD) confirmed a major cyberattack and data leak affecting vehicle-related personal and corporate records. The intrusion represents a critical infrastructure and privacy breach; investigation is ongoing.
- Joint Ukrainian–Latvian action against fraud ring (announcement 25 August). Ukrainian and Latvian authorities reported dismantling an organized criminal call-center operation in Kharkiv that targeted Latvian residents for financial fraud, illustrating cross-border cybercrime exploitation of Latvian victims.
Highest-Risk Areas
Eastern border municipalities dominate the risk ranking, with Rēzekne (68), Daugavpils (65), and Rēzeknes novads (58) leading. These areas are driven by geographic proximity to Belarus and Russia, repeated airspace violations, known smuggling routes, and historical infiltration networks. Secondary-tier risk in municipalities such as Ludzas, Balvu, and Preiļu novads (scores 44–55) reflects similar border vulnerabilities. Riga and western regions, while lower-ranked, face cyber and espionage risk given concentration of NATO facilities, defense contractors, and critical infrastructure.
How GeoBit Would Assist
Corporate security and duty-of-care teams would deploy AOI Monitoring & Early Warning on high-risk border zones and defense-sector facilities to detect airspace incursions, suspicious cross-border activity, and infrastructure anomalies in near-real-time. Network & Actor Analysis and multi-language OSINT (Telegram, local media, police feeds) would track organized crime, hybrid-threat signaling, and sabotage-linked networks. Routing & Network Analysis would identify safer travel corridors and supply-chain alternatives for personnel and assets in Daugavpils, Rēzekne, and Krāslava municipalities.
7-Day Outlook
Russian hybrid activity—airspace probing, sabotage, and cyber operations—is likely to continue at current tempo or escalate as a signaling and destabilization tool. Border interdictions and criminal activity will remain elevated. Vigilance on critical infrastructure (energy, transport, communications) and defense-sector facilities is warranted, particularly in eastern regions.
Highest-Risk Areas — Ranked
| # | State / Region | Risk |
|---|---|---|
| 1 | Rēzekne | 68 |
| 2 | Daugavpils | 65 |
| 3 | Rēzeknes novads | 58 |
| 4 | Ludzas novads | 55 |
| 5 | Balvu novads | 52 |
| 6 | Preiļu novads | 50 |
| 7 | Krāslavas novads | 48 |
| 8 | Jēkabpils novads | 47 |
| 9 | Augšdaugavas novads | 46 |
| 10 | Aizkraukles novads | 45 |
| 11 | Varakļānu novads | 44 |
| 12 | Līvānu novads | 43 |
Sources
Previous Daily Briefs
A new Latvia brief is written every day — each with its own risk map and downloadable CSV. Here's the last week; use the calendar to go further back.
- August 24, 2026
- August 22, 2026
- August 20, 2026
- August 17, 2026
- August 15, 2026
- August 13, 2026
- August 11, 2026
📅 Browse every day by calendar →
Highlighted days have a brief. Tap a day for that day's map & analysis, or “csv” for that day's dataset ($5).
Atlas — our AI intelligence desk — emails them this snapshot personally. Nothing else, no list.