LOUISIANA CYBER INCIDENT WATCHIndependent. Sourced. Local.
BAYOUBREACH
Menu
Back to incident explorer
INCIDENT BRIEF / LAW ENFORCEMENT

East Baton Rouge Parish Sheriff's Office

Confirmed incidentBaton Rouge, LouisianaMar 2024

EBRSO initially described a quickly contained intrusion with limited data loss. In August 2025, Straight Arrow News reported reviewing a much larger leaked collection containing sensitive investigative records. This follow-up materially expands the documented exposure beyond the initial agency account.

01 / OPERATIONAL IMPACT

What happened to the community?

The agency initially acknowledged screenshots and images. SAN subsequently reported reviewing more than 65,000 files, including confidential-informant information. Attribute expanded findings to SAN and avoid reproducing personal details or links to stolen records.

Recovery & current status

On April 2, 2024, EBRSO said public services were operational while security changes could cause interruptions. Current remediation and victim-notification completeness are not established by the reviewed sources.

02 / THE TIMELINE

What the sources document

  1. The agency’s April 2 statement describes detecting an intrusion the preceding Friday. This is not an established initial-access date.

  2. The agency acknowledges limited data loss and says public services are operational.

  3. Straight Arrow News reports a broader sensitive-record exposure after its review of the leaked collection.

03 / EVIDENCE & ATTRIBUTION

What is known. What is claimed.

Medusa's claim is reported in contemporaneous coverage and SAN's follow-up. This does not establish Qilin attribution for the workbook's later listing.

Incident confirmation and attacker attribution are separate questions. A confirmed disruption does not independently verify every claim about stolen data, ransom demands, or responsibility.

04 / FROM INCIDENT TO PREPAREDNESS

Security gap

What to examine in your own environment, and how Fortinet technology could help prevent or limit a similar attack.

Workbook organization match

Sensitive investigative records and controlled data movement

The sheriff’s office acknowledged an intrusion in April 2024. An August 2025 Straight Arrow News investigation reported a broader exposure of sensitive investigative records after reviewing the data. That expanded scope is attributed to the reporting.

What remains unknown: The original entry point and transfer route remain unknown. The workbook matches the organization but its later Qilin listing has not been established as the same event described in reporting about a Medusa claim.

Read the incident evidence
RECOMMENDED FORTINET PRODUCT · WORKBOOK

FortiDLP

Sensitive data movement and egress controls
Cloud platform with endpoint agents

Cloud-native data-protection platform using endpoint agents and supported cloud integrations; not a universal inline appliance for all server traffic.

Why it fits: The workbook’s account-level recommendation is to identify sensitive justice records and control covered transfer paths. Data classification, policy enforcement and investigation context can reduce exposure in a similar scenario. This organization match is not proof of the historical attack path.

How the technology works: Inspects sensitive data and user activity through endpoint agents and supported cloud integrations, using content, origin, and behavioral context to flag risky movement and enforce controls on covered egress paths.

For it to help: Coverage follows deployed agents and supported integrations or egress paths; it is not universal exfiltration blocking for arbitrary servers or unseen traffic.

Before choosing a model or license
  • Which devices, cloud drives, and egress paths need coverage?
  • What data is sensitive?
  • Which policies can safely block activity?

Choose the capacity and license after reviewing these requirements. This brief does not prescribe an appliance model or promise a historical attack would have been prevented.

Additional controls to validate 3 conditional options
CONDITIONAL FOLLOW-ON

FortiEDR

Endpoint prevention, containment, and response
Endpoint software with cloud or on-premises management

Software agents protect supported endpoints and servers; management components can be cloud, on-premises, or hybrid. This is not an inline hardware firewall.

Why it fits: Behavior-based protection and isolation can help contain harmful activity on supported workstations and servers; endpoint coverage must be verified.

How the technology works: An endpoint agent analyzes malware and suspicious process behavior, can block harmful file access and outbound communications, and supports automated isolation and remediation to limit ransomware damage on protected devices.

For it to help: Protection depends on supported devices running the agent with suitable prevention and response policies; this does not guarantee every ransomware attack is stopped.

CONDITIONAL FOLLOW-ON

FortiPAM

Privileged credential and session controls
Virtual appliance

The current datasheet identifies a virtual appliance for privileged credential and session management. Do not label it a recommended physical box.

Why it fits: If administrator or vendor privilege is an identified gap, vaulted credentials, approvals and recorded sessions can reduce misuse. Privileged-account compromise is not established here.

How the technology works: Vaults and rotates privileged credentials, brokers access under role-based policies, and records privileged sessions; administrators can restrict commands or terminate sessions to reduce credential exposure and misuse of elevated access.

For it to help: Apply these controls to onboarded accounts and brokered sessions; unmanaged credentials or direct access that bypasses FortiPAM remain outside that enforcement path.

CONDITIONAL FOLLOW-ON

FortiNDR

Network behavior detection and response support
Hardware/VM sensors; on-premises platform or cloud service

FortiNDR offers on-premises hardware and VM deployments; FortiNDR Cloud is SaaS with supported hardware or virtual sensors. Sensor placement determines the traffic available for analysis.

Why it fits: Assess network detection for server and network paths not covered by endpoint agents. Confirm sensor visibility and who can investigate and contain an alert.

How the technology works: Analyzes observed network traffic to detect signs of lateral movement, command activity, and data exfiltration, providing investigation context and integrations that help security teams coordinate containment with enforcement tools.

For it to help: Detection depends on sensor visibility into relevant traffic; containment requires an enabled response workflow or integration with an enforcement tool.

ASK YOUR IT TEAM OR SERVICE PROVIDER

Which shared locations contain investigative records, who can export them, and can your team demonstrate controls on those transfer paths?

Request conversation
Mapping & assessment notes

Prepared using Five_State_Ransomware_Fortinet_Positioning.xlsx, October 8, 2026 snapshot.

Louisiana account row 11; listing evidence row 40; evidence ID RL-17388. The lead product and conditional follow-ons follow that account row. FortiToken is explained alongside FortiAuthenticator using current vendor documentation.

Matched to the organization identified in the workbook. This does not independently establish that the listing describes this historical incident.

Workbook’s provider record

These are present-day control examples, reviewed October 9, 2026. “Security gap” means an area to evaluate, not a proven failure at the named organization. Products, configurations, historical availability and the actual attack path vary. No product is asserted to have certainly prevented this incident.

How we assess control fit
05 / READ THE ORIGINALS

Sources & further reading