15min already wrote that the law firm “HUB Legal”, inviting victims of the Register Center data theft to join a collective lawsuit, is preparing a group complaint.
Read more “Neurobics” test: do you know these 5 songs by Justinas Jaručys?
As 15min was informed by HUB Legal’s managing partner Laurynas Lukošiūnas, it was submitted on Monday to the Vilnius branch of the Regional Administrative Court.
According to the latest data, 1337 residents have joined the group complaint.
“In total, about four thousand people contacted us, and more than 1300 people have already joined the complaint and signed representation agreements,” said L. Lukošiūnas.
According to him, the complaint acceptance stage is now beginning.
“They may identify deficiencies, ask for clarifications. After accepting the complaint, the court sets a deadline – usually 2–3 months – to join the complaint. So those who have not yet joined should not worry – they will have that right,” informed L. Lukošiūnas.
The group complaint demands compensation for non-material damage to the affected residents whose data was stolen. The lawyers submitting the group complaint plan to request 5000 euros in non-material damage compensation from the Register Center, the Ministry of Justice, and the Migration Department for each affected person – which would already amount to 6.7 million euros.

The lawyer added that the complaint was also supplemented with individuals’ personal experiences.
“We see that it was not as simple as it might seem to some less sensitive person – the affected people really experienced distress, feel very uncomfortable, and believe it should not have happened. I would say this is a matter of trust in the state. You trust the state, trust its systems, trust that such data is protected. People are really outraged and combative – many of them call, write, and hope that the state will admit the mistake,” said L. Lukošiūnas.
According to him, there is currently no evidence of material damage (for example, if someone used the data to take out a loan), but the complaint can be supplemented later – the statute of limitations is three years.
“We have no doubt that leaked personal codes, residential addresses are already on the dark web, which causes a justified feeling of insecurity. The state did not fulfill its duties, trust is lost. Abroad, such sensitive data leaks are viewed very strictly,” added L. Lukošiūnas.
An unprecedented case
According to L. Lukošiūnas, the massive data leak from the registers managed by the Register Center is the first such case in Lithuania.
Read more Mia reported unpleasant news
“There is no precedent, so we follow foreign examples. The Court of Justice of the European Union has taken a very strict stance on data sensitivity. This will be a unique case even on the scale of the European Union. It certainly will not be simple and may be examined for many years. It may be necessary to seek clarifications from the EU Court of Justice, go through several instances,” said L. Lukošiūnas, prepared for a long process.

The lawyers who prepared the group complaint work on a success fee basis – this means that the affected residents who joined the group complaint will not have to pay for legal services, but in case of success, if the courts award them compensation, the lawyers will take 30% of that amount as a fee.
However, there is a small, more theoretical risk, according to L. Lukošiūnas, that if the lawyers lose the case and the state hires external lawyers, the court could award their costs to all members of the group who submitted the complaint.
600 thousand data leaked
The scandal over the Register Center data leak arose in May, when the 15min portal was the first to report on the incident.
However, although the affected residents learned about the stolen data only in May, unauthorized access to the registers managed by the Register Center occurred much earlier – from January to April.
According to law enforcement data, more than 600 thousand Real Estate Register entries were illegally accessed and downloaded over several months through accounts of Migration Department employees hacked from abroad. The institution learned about the possible incident in early April, and the public was informed only at the end of May.
The leaked data included residents’ names, surnames, personal codes, birth dates, real estate addresses, register numbers, cadastral data, as well as information about property rights and their registration basis. The Register Center emphasized that no contact details, bank account numbers, payment information, or documents related to property transactions were disclosed. The company also stated that there was no hacking into the Register Center’s own systems – access to data was allegedly obtained through legitimate user accounts held by the Migration Department.
Due to this case, the General Prosecutor’s Office initiated a pre-trial investigation, and the State Data Protection Inspectorate started its own investigation. Questions arose in the public space not only about the scale of the leak itself but also about why residents were informed about the incident late.
The incident already had political consequences – after the scandal became public, the head of the Register Center, Adrijus Jusas, resigned.