
Situation Summary
Latvia faces a sustained hybrid-threat environment characterized by airspace violations, border incursions, and cyber intrusions rather than conventional military escalation. While national leadership has publicly stated that direct Russian invasion risk remains low, official statements and concrete incidents over the past 48 hours confirm elevated concern about sabotage, cyberattacks, drone activity, and cross-border infiltration. The eastern border region remains the primary zone of friction, with Latvia's government considering temporary emergency measures in critical sectors through December 2026.
Key Developments
- Airspace incident (national, 26 August): NATO air defence shot down an unidentified unmanned aerial vehicle carrying explosives after it violated Latvian airspace, reportedly originating from Belarus. The incident remains central to official threat discourse as of 28 August.
- Emergency-regime proposal (eastern border regions, 27–28 August): Latvia's Climate and Energy Ministry drafted a temporary state-of-emergency order for healthcare, energy, and water sectors in eastern border areas until 1 December, citing airspace and hybrid threats. The ministry withdrew the draft on 28 August for revision following public concern, but the intent signals elevated official threat assessment.
- Border-tunnel operation (Krāslava and Skrudaliena, Augšdaugava, reported 28 August): Security services publicly confirmed discovery of two underground tunnels on the Latvia–Belarus border used for illegal migrant crossings, with Belarusian authorities allegedly complicit. Twenty-eight individuals were detained; the finding is part of Operation "Vilkatis," launched 11 August.
- CSDD cyberattack scope confirmed (Riga, incident 7–8 August, disclosed 28 August): The Road Traffic Safety Directorate detailed a major breach affecting ~1.2 million individuals and 200,000 legal entities. The attacker gained entry via a medical-certification platform; compromised data includes personal ID numbers, names, addresses, and vehicle registration details.
- Suspected sabotage by Latvian national (Slovakia, reported 27–28 August): German authorities detained a 26-year-old Latvian citizen suspected in an arson plot against a Ukrainian drone manufacturer's factory in Slovakia, indicating possible foreign-directed sabotage activity involving Latvian nationals.
- Leadership threat assessment (national, 27–28 August): President Rinkēvičs and Prime Minister Kulbergs publicly reiterated that while direct invasion risk is low, Latvia faces persistent threats from sabotage, cyberattacks, and hybrid operations including drones and unidentified airspace incursions.
Highest-Risk Areas
Eastern and southeastern border municipalities dominate the risk profile: Rēzekne (risk 68), Daugavpils (65), and Rēzeknes novads (58) lead sub-national rankings, followed by Ludzas novads (55) and Balvu novads (52). These areas share proximity to Belarus and Russia, coinciding with reported drone sightings, tunnel discoveries, and hybrid-pressure operations. The concentration of risk in the east reflects both physical border vulnerability and alleged Belarusian-facilitated infiltration routes; Krāslava and Augšdaugava novads, both implicated in recent tunnel findings, appear in the top-12 risk ranking.
How GeoBit Would Assist
Intel Sweep and multi-language OSINT fusion enable continuous monitoring of Latvian-language security announcements, military disclosures, and border-region reporting to identify emerging hybrid threats ahead of mainstream media. AOI Monitoring & Early Warning applied to eastern border municipalities and critical infrastructure locations (power, healthcare, transport hubs) would provide persistent alerting on airspace incidents, unusual cross-border activity, and cyber indicators. Network & Actor Analysis supports identification of sabotage networks and foreign-directed influence campaigns, while Routing & Network Analysis assists duty-of-care teams in planning safe alternative routes and supply chains around high-risk border zones.
7-Day Outlook
Emergency measures in border-region critical sectors are likely to be formalized within days following the ministry's revision process. Airspace incidents and hybrid probing are expected to persist through late August and September as part of ongoing pressure. Organizations with staff or assets in eastern Latvia should implement heightened contingency protocols for cyberattacks, supply-chain disruption, and infrastructure service interruptions.
Highest-Risk Areas — Ranked
| # | State / Region | Risk |
|---|---|---|
| 1 | Rēzekne | 68 |
| 2 | Daugavpils | 65 |
| 3 | Rēzeknes novads | 58 |
| 4 | Ludzas novads | 55 |
| 5 | Balvu novads | 52 |
| 6 | Preiļu novads | 50 |
| 7 | Krāslavas novads | 48 |
| 8 | Jēkabpils novads | 47 |
| 9 | Augšdaugavas novads | 46 |
| 10 | Aizkraukles novads | 45 |
| 11 | Varakļānu novads | 44 |
| 12 | Līvānu novads | 43 |
Sources
Previous Daily Briefs
A new Latvia brief is written every day — each with its own risk map and downloadable CSV. Here's the last week; use the calendar to go further back.
- August 26, 2026
- August 24, 2026
- August 22, 2026
- August 20, 2026
- August 17, 2026
- August 15, 2026
- August 13, 2026
📅 Browse every day by calendar →
Highlighted days have a brief. Tap a day for that day's map & analysis, or “csv” for that day's dataset ($5).
Atlas — our AI intelligence desk — emails them this snapshot personally. Nothing else, no list.