Balticom cyber attack hijacks interactive TV streams via Bulgarian server
Latvian communications operator Balticom experienced a cyber attack on an interactive TV server hosted in Bulgaria, resulting in the unauthorized broadcast of Russian propaganda to 5% of its subscribers. Investigations by Cert.lv confirmed the breach occurred at a third-party content delivery partner rather than within Balticom's internal infrastructure.
Key Takeaways
- Unauthorized Kremlin propaganda replaced scheduled programming for 5% of Balticom interactive TV subscribers.
- Cert.lv confirmed the breach occurred at a third-party content delivery partner in Bulgaria rather than Balticom's internal network.
- The incident follows a similar April 17 breach where the Tet platform's satellite signal for the Freedom channel was compromised.
- National Electronic Mass Media Council chairman Ivars Āboliņš reported the operator temporarily lost control of all retransmissions during the event.
Why It Matters
This breach highlights a critical vulnerability in the streaming supply chain where secure internal infrastructure is bypassed by compromising third-party content delivery partners. As streaming operators increasingly rely on geographically distributed server networks, the attack surface for state-sponsored hybrid warfare expands beyond national borders. The incident underscores that platform security is only as strong as the weakest link in the IP television distribution chain. Industry observers should monitor for new security mandates from the National Electronic Mass Media Council regarding the vetting of international hosting providers and satellite signal redundancy.
Additional Context
Balticom operates as one of Latvia's largest telecommunications and interactive TV providers, competing directly with Tet in the Baltic IPTV market. The attack on its Bulgarian-hosted content delivery infrastructure reflects a broader pattern of state-sponsored interference targeting Baltic media distribution systems. In 2024, Latvia's National Electronic Mass Media Council revoked licenses for multiple channels broadcasting Russian propaganda content following regulatory enforcement actions, signaling heightened scrutiny of content integrity across the country's broadcast and streaming platforms. The incident at Balticom adds urgency to ongoing discussions about supply-chain security in distributed IPTV architectures.
The regulatory response to hybrid threats against Baltic media infrastructure has intensified since Russia's full-scale invasion of Ukraine in 2022. Latvia's Cert.lv, the national cybersecurity incident response team, has been at the forefront of coordinating responses to politically motivated cyber operations targeting critical infrastructure. The European Union's NIS2 Directive, which entered into force in January 2023, requires member states to impose stricter security obligations on digital infrastructure providers, including content delivery networks and managed service providers. For operators like Balticom that rely on third-party hosting partners in other EU member states, NIS2 compliance creates new obligations around vendor risk assessment and incident reporting timelines that could reshape how IPTV providers select and audit their CDN partners.
From a technical perspective, the Balticom breach illustrates a known vulnerability class in IPTV delivery architectures where content originates from centralized servers but is distributed through geographically dispersed edge nodes. Research published by the European Union Agency for Cybersecurity (ENISA) in 2024 identified supply-chain attacks on media distribution infrastructure as a growing threat vector, particularly for operators serving audiences in NATO's eastern flank. The attack methodology, involving compromise of a third-party server rather than the operator's own systems, mirrors techniques documented in hybrid warfare playbooks where adversaries target the weakest link in a content delivery chain to maximize psychological impact with minimal technical footprint. For streaming operators across the Baltics and broader Eastern Europe, the incident reinforces the need for cryptographic content verification and real-time stream integrity monitoring at every hop in the delivery pipeline. Future compliance efforts will likely be shaped by which will require faster incident disclosure.
Read full article at eng.lsm.lv
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source