LOUISIANA CYBER INCIDENT WATCHIndependent. Sourced. Local.
BAYOUBREACH
Menu
Back to incident explorer
INCIDENT BRIEF / LOCAL GOVERNMENT

City of New Orleans

Confirmed incidentNew Orleans, LouisianaDec 13, 2019

New Orleans shut down its municipal network after detecting ransomware and declared an emergency. Departments moved some work to paper. City updates described disrupted permitting, records access and other services, while emergency response and the communications district continued operating throughout.

01 / OPERATIONAL IMPACT

What happened to the community?

The December 16 city update described manual police reports and permit processes, interrupted public background checks, and unavailable electronic records preventing Healthcare for the Homeless from seeing patients. Emergency response remained operational.

Recovery & current status

Historical service impacts as of December 16, 2019; no present-day outage claim.

02 / THE TIMELINE

What the sources document

  1. The city detected ransomware, shut down its network and declared an emergency.

  2. The city published department-by-department service updates, including manual processes and records-access interruptions.

03 / EVIDENCE & ATTRIBUTION

What is known. What is claimed.

No actor identified in the cited contemporaneous sources. ABC reported that perpetrators were unidentified at the December 13 press conference. This record makes no later attribution finding.

Incident confirmation and attacker attribution are separate questions. A confirmed disruption does not independently verify every claim about stolen data, ransom demands, or responsibility.

04 / FROM INCIDENT TO PREPAREDNESS

Security gap

What to examine in your own environment, and how Fortinet technology could help prevent or limit a similar attack.

Separate technical assessment

Endpoint containment during ransomware disruption

Public records describe a ransomware event and the city’s protective shutdown of systems. The service disruption supports reviewing endpoint containment and continuity.

What remains unknown: The cited record does not establish a complete intrusion path or the controls deployed at the time. There is no matching Louisiana account row in the workbook.

Read the incident evidence
RECOMMENDED FORTINET PRODUCT · ASSESSMENT

FortiEDR

Endpoint prevention, containment, and response
Endpoint software with cloud or on-premises management

Software agents protect supported endpoints and servers; management components can be cloud, on-premises, or hybrid. This is not an inline hardware firewall.

Why it fits: The workbook’s general endpoint guidance fits this ransomware scenario: blocking harmful process behavior and isolating covered devices could limit damage in a similar event.

How the technology works: An endpoint agent analyzes malware and suspicious process behavior, can block harmful file access and outbound communications, and supports automated isolation and remediation to limit ransomware damage on protected devices.

For it to help: Protection depends on supported devices running the agent with suitable prevention and response policies; this does not guarantee every ransomware attack is stopped.

Before choosing a model or license
  • Which endpoint operating systems and workloads are supported?
  • How many devices need protection?
  • Who monitors alerts and authorizes isolation?

Choose the capacity and license after reviewing these requirements. This brief does not prescribe an appliance model or promise a historical attack would have been prevented.

Additional controls to validate 1 conditional options
CONDITIONAL FOLLOW-ON

FortiGate segmentation + IPS

Network access restriction and exploit filtering
Hardware or virtual firewall

Physical FortiGate appliances suit on-site network enforcement; FortiGate-VM supports private and public clouds. This classification does not select a model or claim all deployment types share identical capacity.

Why it fits: Separating critical service networks and restricting communications can limit reachable systems if an intruder gains a foothold. This does not establish that segmentation failed in 2019.

How the technology works: Separates network segments with firewall policies that restrict allowed communications, while IPS inspects traversing traffic for attack patterns and can block matching exploits, helping contain lateral movement between protected zones.

For it to help: Traffic must cross the enforcement point, with restrictive policies and IPS enabled; encrypted payload inspection needs appropriate decryption and inspection configuration.

ASK YOUR IT TEAM OR SERVICE PROVIDER

Can your team test isolation of an infected administrative device while keeping essential public-safety services operating?

Request conversation
Mapping & assessment notes

Prepared using Five_State_Ransomware_Fortinet_Positioning.xlsx, October 8, 2026 snapshot.

No matching Louisiana account row was found. This assessment applies the workbook’s general product guidance and linked technical sources; it is not presented as an account recommendation from the sheet.

These are present-day control examples, reviewed October 9, 2026. “Security gap” means an area to evaluate, not a proven failure at the named organization. Products, configurations, historical availability and the actual attack path vary. No product is asserted to have certainly prevented this incident.

How we assess control fit
05 / READ THE ORIGINALS

Sources & further reading