What happened to the community?
Containment disabled state websites, email and other services. A November 26 agency notice confirmed its billing portal remained unavailable and announced a temporary service-order freeze.
These sources describe historical conditions. Current operational and recovery status has not been established in this record.
What the sources document
Officials detected ransomware and disabled state servers as part of containment.
An official notice described continued billing-portal interruption and a temporary service-order freeze.
What is known. What is claimed.
StateScoop reported officials identified Ryuk malware. Ryuk is a ransomware family here; this is not attribution to a named individual or nation. Outages included deliberate containment, not only direct encryption effects. Historical restoration predictions are not current status.
Incident confirmation and attacker attribution are separate questions. A confirmed disruption does not independently verify every claim about stolen data, ransom demands, or responsibility.
The provider record.
Source: Ransomware.live · Last successful check Oct 9, 2026
These are provider-recorded allegations, not independent findings about the attacker or stolen data. Dates below show when the provider observed a listing.
Louisiana Office of Technology Services
Ransomware.live records a listing attributed to ryuk, observed Nov 18, 2019. Bayou Breach has not independently verified the group’s allegations.
Louisiana officials shut down state servers after detecting ransomware on November 18, 2019. Websites, email and online services were interrupted. StateScoop reported Ryuk malware; an official notice documented billing disruption.
An organization match alone does not establish that this listing describes the same event.
StateScoop: read the reportingMatched against a reviewed Louisiana organization directory. This is a limited supplementary source watch, not a statewide census. A scheduled task checks every hour, including while the site is closed. Visits can also refresh a stale snapshot, with at most one refresh attempt per clock hour. No raw-data feed is offered.
Security gap
What to examine in your own environment, and how Fortinet technology could help prevent or limit a similar attack.
Contain endpoint activity while preserving state services
The workbook’s lead recommendation is FortiEDR, supported by reported ransomware disruption and an official recovery notice describing unavailable services.
What remains unknown: The recovery notice does not provide the complete intrusion path or establish a stolen-data scope. Current endpoint coverage is unknown.
Read the incident evidenceFortiEDR
Endpoint prevention, containment, and responseSoftware agents protect supported endpoints and servers; management components can be cloud, on-premises, or hybrid. This is not an inline hardware firewall.
Why it fits: Endpoint behavior analysis, harmful-process blocking and isolation can help contain a similar ransomware event on protected systems. The workbook calls for checking supported server and workstation coverage first.
How the technology works: An endpoint agent analyzes malware and suspicious process behavior, can block harmful file access and outbound communications, and supports automated isolation and remediation to limit ransomware damage on protected devices.
For it to help: Protection depends on supported devices running the agent with suitable prevention and response policies; this does not guarantee every ransomware attack is stopped.
Before choosing a model or license
- Which endpoint operating systems and workloads are supported?
- How many devices need protection?
- Who monitors alerts and authorizes isolation?
Choose the capacity and license after reviewing these requirements. This brief does not prescribe an appliance model or promise a historical attack would have been prevented.
Additional controls to validate 3 conditional options
FortiAuthenticator + FortiToken
Stronger authentication and centralized identity policyFortiAuthenticator is available as a physical or virtual appliance, including private/public-cloud deployment. FortiToken factors include mobile software and hardware tokens or security keys.
Why it fits: Relevant if authentication weaknesses are verified for integrated agency or administrative access; the entry method is not established here.
How the technology works: Centralizes authentication for integrated applications, VPNs, and administrative access, adding FortiToken factors and identity policies so a stolen password alone is less likely to provide access to protected resources.
For it to help: Phishing resistance requires an appropriate FIDO2 flow; OTP or push alone is not equivalent. Enabling MFA does not establish revocation of already stolen application sessions.
FortiRecon
Exposure discovery and adversary intelligenceSubscription exposure-management and intelligence service; not a physical network appliance.
Why it fits: External-asset and credential intelligence can inform remediation of validated exposures. Monitoring is not an endpoint blocking control.
How the technology works: Continuously discovers exposed assets and prioritizes vulnerabilities, while monitoring leaked credentials, ransomware activity, and other adversary intelligence so teams can remediate exposure and investigate emerging risk before or during an incident.
For it to help: Findings require investigation and remediation; exposure monitoring and ransomware intelligence do not directly block ransomware execution.
FortiDLP
Sensitive data movement and egress controlsCloud-native data-protection platform using endpoint agents and supported cloud integrations; not a universal inline appliance for all server traffic.
Why it fits: The workbook makes this conditional on confirmed copied data and a validated, supported data-protection scope.
How the technology works: Inspects sensitive data and user activity through endpoint agents and supported cloud integrations, using content, origin, and behavioral context to flag risky movement and enforce controls on covered egress paths.
For it to help: Coverage follows deployed agents and supported integrations or egress paths; it is not universal exfiltration blocking for arbitrary servers or unseen traffic.
Can each agency show endpoint coverage, ownership of isolation decisions and a tested path for restoring priority services?
Request conversationMapping & assessment notes
Prepared using Five_State_Ransomware_Fortinet_Positioning.xlsx, October 8, 2026 snapshot.
Louisiana account row 28; listing evidence row 59; evidence ID RL-32404. The lead product and conditional follow-ons follow that account row. FortiToken is explained alongside FortiAuthenticator using current vendor documentation.
The workbook’s provider permalink identifies the matching listing. An API match requires that exact record ID and the reviewed organization, not a shared attacker name.
Workbook’s provider recordThese are present-day control examples, reviewed October 9, 2026. “Security gap” means an area to evaluate, not a proven failure at the named organization. Products, configurations, historical availability and the actual attack path vary. No product is asserted to have certainly prevented this incident.
How we assess control fit