According to bb.lv, citing the president's advisor, Rinkevics made the decision to grant clemency on September 15. The president reviewed the court decisions in the case and, as his advisor emphasized, does not question their legality. However, in making his decision, Rinkevics took into account the importance of the security of state information systems, the obligation of state institutions to promptly address vulnerabilities, and the public interest in ensuring that people report discovered cybersecurity issues in good faith. In the president's assessment, the benefit to society from Skuruls' actions was significantly greater than the severity of the offense he committed. Based on Article 45 of the Constitution and the Law on Clemency, Rinkevics released Skuruls from serving the main punishment and lifted his conviction. ### Vulnerability discovered back in 2018 The story began in the fall of 2018. Skuruls informed CSDD that he had discovered a potential vulnerability in the authorization mechanism for electronic services related to the state register of vehicles and their drivers. According to data previously provided by Latvijas Avīze, he was initially redirected multiple times from one CSDD employee to another. Eventually, the IT company WeAreDots was brought into the conversation. Skuruls claimed that he spent many hours researching the problem and did not want to provide the results for free. He requested 1000 euros for the information. A contract was signed between his company Acoustic Power LAB and WeAreDots: Skuruls was to provide materials, specialists were to verify the existence of the vulnerability, and if confirmed, he would be allowed to issue an invoice for 1000 euros. After signing the contract, Skuruls provided information about the flaw in the e-CSDD authorization mechanism, which potentially allowed unauthorized access to certain actions. At the same time, the charge of attempting to disrupt the information system, for which he was initially suspected, was not brought against him later. ### Media warning became part of the criminal case The situation was complicated by the fact that during communication with CSDD representatives, Skuruls stated that if the problem was not resolved, he would inform the Latvian public about the vulnerability through the media. In late October 2018, CSDD management contacted the State Police, after which a criminal investigation was initiated. Skuruls was detained and placed in a temporary detention facility for several days. The case went through several judicial instances. At one point, the appellate court acquitted Skuruls, but after the prosecution's cassation, the Supreme Court overturned this decision and sent the case for re-examination. In early September 2026, the verdict of the Vidzeme District Court came into force, according to which Skuruls was found guilty of extortion and received a fine of 4290 euros. ### Inventor with a prestigious award Raimonds Skuruls is a radio engineer and design engineer. For one of his inventions, he was previously awarded the prestigious Walter Zapp Prize, established by the Latvian Academy of Sciences and the Patent Office. Almost eight years after discovering the vulnerability, the case had an unusual resolution: the president did not challenge the court's conclusions but exercised his right to grant clemency. The key argument was that the good-faith discovery and disclosure of vulnerabilities in state IT systems serves the interests of society and the country's cybersecurity.