Verified cyberincident context · Latvia / CERT.LV Q4 2025
Latvia CERT.LV Q4 2025 cybersecurity activity context
Market context — not industry-specific evidence
Latvia CERT.LV activity review Q4 2025 context (published 2026-02-16) states that CERT.LV manually processed 923 cyber incidents in Q4 2025, a 62% increase compared with the previous comparison period. CERT.LV recorded 731,783 compromised devices during Q4 2025 — the number of compromised devices increased eightfold during the reporting period. The CERT.LV DNS firewall blocked 1.03 million attempted visits to malicious websites during Q4 2025. All these figures are Q4 2025 context only and must not be presented as full-year 2025 totals, long-term trend conclusions, all cyber incidents in Latvia, or total Latvian business incident prevalence.
Manually processed cyber incidents by CERT.LV — Latvia Q4 2025
- Manually processed cyber incidents by CERT.LV in Q4 2025
- 923
- Unit
- manually processed cyber incidents by CERT.LV in Q4 2025
- Period
- Latvia CERT.LV Q4 2025 quarterly manually processed cyber incident, compromised-device, and DNS-firewall activity context.
- Scope
- Latvia CERT.LV Q4 2025 cybersecurity activity context
Q4 2025 context only. This value refers to manually processed incidents and is not a count of all cyber incidents in Latvia.
CERT.LV Q4 2025 quarterly manually processed cyber incident context only. The 923 value refers to manually processed cyber incidents by CERT.LV in Q4 2025 only and must not be presented as all cyber incidents in Latvia, a full-year 2025 total, or total Latvian business incident prevalence. Not industry-specific evidence.
Year-on-year increase in CERT.LV manually processed incidents — Latvia Q4 2025
- 62% increase in CERT.LV manually processed cyber incidents in the Q4 2025 reporting period compared with the previous comparison period
- 62%
- Unit
- percent increase in manually processed cyber incidents in the CERT.LV Q4 2025 reporting period compared with the previous comparison period
- Period
- Latvia CERT.LV Q4 2025 quarterly manually processed cyber incident, compromised-device, and DNS-firewall activity context.
- Scope
- Latvia CERT.LV Q4 2025 cybersecurity activity context
CERT.LV Q4 2025 quarterly incident year-on-year change context only. The 62% value is a quarterly comparison for the Q4 2025 reporting period and must not be presented as a full-year trend, a measure of all-Latvia cyberattack volume change, or total Latvian business incident trend. Not industry-specific evidence.
Compromised devices recorded by CERT.LV — Latvia Q4 2025
- Compromised devices recorded by CERT.LV during Q4 2025
- 731,783
- Unit
- compromised devices recorded by CERT.LV during Q4 2025
- Period
- Latvia CERT.LV Q4 2025 quarterly manually processed cyber incident, compromised-device, and DNS-firewall activity context.
- Scope
- Latvia CERT.LV Q4 2025 cybersecurity activity context
The number of compromised devices increased eightfold during the Q4 2025 reporting period. This refers to compromised devices recorded by CERT.LV in Q4 2025 and must not be presented as a long-term trend conclusion.
CERT.LV Q4 2025 quarterly compromised-device observation context only. The 731,783 value refers to compromised devices recorded during Q4 2025 and must not be presented as confirmed breached organisations, resolved incidents, total Latvian business incident prevalence, or a full-year total. Not industry-specific evidence.
DNS firewall blocked attempted visits to malicious websites — Latvia Q4 2025
- Blocked attempted visits to malicious websites recorded by the CERT.LV DNS firewall during Q4 2025 (source states 1.03 million)
- 1,030,000
- Unit
- blocked attempted visits to malicious websites recorded by the CERT.LV DNS firewall during Q4 2025 — source states 1.03 million
- Period
- Latvia CERT.LV Q4 2025 quarterly manually processed cyber incident, compromised-device, and DNS-firewall activity context.
- Scope
- Latvia CERT.LV Q4 2025 cybersecurity activity context
The CERT.LV DNS firewall blocked 1.03 million attempted visits to malicious websites during Q4 2025. This is Q4 2025 activity context only.
CERT.LV Q4 2025 quarterly DNS firewall activity context only. The 1,030,000 value refers to blocked attempted visits to malicious websites during Q4 2025 and must not be presented as protected organisations, resolved incidents, proof of protection, total Latvian business incident prevalence, or a full-year total. Not industry-specific evidence.
Source: CERT.LV, CERT.LV activity review Q4 2025, 16 February 2026
Scope: CERT.LV quarterly activity review published 2026-02-16. All admitted metrics are Q4 2025 context only; none represent full-year 2025 values, annual totals, or long-term trend conclusions. The 923 manually processed incidents must not be presented as all cyber incidents in Latvia. The 62% increase is a quarterly comparison for the Q4 2025 period only. The 731,783 compromised devices must not be presented as confirmed breached organisations, resolved incidents, or total Latvian business incident prevalence. The eightfold increase in compromised devices is a within-period observation only. The 1,030,000 DNS firewall count must not be presented as protected organisations, resolved incidents, or proof of protection. These figures do not measure total Latvian business incident prevalence, hidden incident prevalence, population-wide victimisation rates, all-sector incident totals, industry-specific evidence, compliance achievement, certification, or security outcomes.
Methodology: Official CERT.LV quarterly activity review published 2026-02-16. The admitted indicators describe CERT.LV Q4 2025 quarterly manually processed cyber incidents, compromised devices recorded, and DNS firewall protection activity. All admitted metrics are Q4 2025 context only and must not be presented as full-year 2025 values, annual totals, or long-term trend conclusions. The 923 value refers to manually processed cyber incidents by CERT.LV in Q4 2025 only and must not be presented as all cyber incidents in Latvia. The 62% increase is a quarterly comparison for the Q4 2025 reporting period and must not be presented as a full-year trend or a measure of all-Latvia cyberattack volume change. The 731,783 value refers to compromised devices recorded during Q4 2025 and must not be presented as confirmed breached organisations, resolved incidents, or total Latvian business incident prevalence. The eightfold increase in compromised devices is a within-period observation and must not be presented as a long-term trend conclusion. The 1,030,000 DNS firewall protection count refers to blocked attempted visits to malicious websites during Q4 2025 and must not be presented as protected organisations, resolved incidents, or proof of protection. Do not present any admitted indicator as total Latvian business incident prevalence, hidden incident prevalence, population-wide victimisation rate, all-sector incident rate, all-Latvia cyberattack volume, industry-specific evidence, compliance achievement, certification, proof of security, or guaranteed protection.
Accessible data table
| Metric | Value | Source | Scope | Reporting period |
|---|---|---|---|---|
| Manually processed cyber incidents by CERT.LV in Q4 2025 | 923 manually processed cyber incidents by CERT.LV in Q4 2025 | CERT.LV, CERT.LV activity review Q4 2025, 16 February 2026 | Latvia CERT.LV Q4 2025 cybersecurity activity context | Latvia CERT.LV Q4 2025 quarterly manually processed cyber incident, compromised-device, and DNS-firewall activity context. |
| 62% increase in CERT.LV manually processed cyber incidents in the Q4 2025 reporting period compared with the previous comparison period | 62% percent increase in manually processed cyber incidents in the CERT.LV Q4 2025 reporting period compared with the previous comparison period | CERT.LV, CERT.LV activity review Q4 2025, 16 February 2026 | Latvia CERT.LV Q4 2025 cybersecurity activity context | Latvia CERT.LV Q4 2025 quarterly manually processed cyber incident, compromised-device, and DNS-firewall activity context. |
| Compromised devices recorded by CERT.LV during Q4 2025 | 731,783 compromised devices recorded by CERT.LV during Q4 2025 | CERT.LV, CERT.LV activity review Q4 2025, 16 February 2026 | Latvia CERT.LV Q4 2025 cybersecurity activity context | Latvia CERT.LV Q4 2025 quarterly manually processed cyber incident, compromised-device, and DNS-firewall activity context. |
| Blocked attempted visits to malicious websites recorded by the CERT.LV DNS firewall during Q4 2025 (source states 1.03 million) | 1,030,000 blocked attempted visits to malicious websites recorded by the CERT.LV DNS firewall during Q4 2025 — source states 1.03 million | CERT.LV, CERT.LV activity review Q4 2025, 16 February 2026 | Latvia CERT.LV Q4 2025 cybersecurity activity context | Latvia CERT.LV Q4 2025 quarterly manually processed cyber incident, compromised-device, and DNS-firewall activity context. |
| Latvia CERT.LV activity review Q4 2025 context states that the number of compromised devices increased eightfold during the Q4 2025 reporting period. The value field stores 8 as the stated multiplier. The "eightfold" qualifier is stated in the unit string and must be preserved. This metric is admitted to records for completeness but must not be charted as a bar; it is referenced in supporting text for the compromised-devices block only. Must not be presented as a long-term trend conclusion. | 8 times increase in compromised devices recorded by CERT.LV during Q4 2025 compared with the previous comparison period — source states eightfold increase | CERT.LV, CERT.LV activity review Q4 2025, 16 February 2026 | Latvia CERT.LV Q4 2025 cybersecurity activity context | Latvia CERT.LV Q4 2025 quarterly manually processed cyber incident, compromised-device, and DNS-firewall activity context. |
