The affected information system is the "Remote Statistical Data Retrieval System" (SUPSD). SUPSD has a security class of C, which is the lowest risk level for an information system. This system is used by the Consumer Rights Protection Center (CRPC) to oversee licensed merchants, and it meets the minimum cybersecurity requirements established in the country. SUPSD is hosted within a network infrastructure that has an early warning sensor system for preventing cyber incidents, "Cert.lv." The investigation conducted so far indicates that as a result of the incident, contact information of licensed CRPC entities was obtained: providers of consumer credit services, providers of out-of-court debt collection services, and providers of comprehensive tourism services. The attackers gained access to the contact information of 697 representatives of merchants and 34 officials of the CRPC - first name, last name, email address, and phone number. In most cases, this information is available in other public registers, such as on the open data portal. As a result of the incident, the data subject to oversight that merchants submitted to the CRPC was not compromised. Currently, the affected system is closed. The CRPC has informed all users of the system about its unavailability. The CRPC emphasizes that in the unstable geopolitical situation, it is extremely important to enhance the security of any technological resources by finding the necessary financial means, as previously pointed out by the Ministry of Economics at a Cabinet meeting on cybersecurity.