LOUISIANA CYBER INCIDENT WATCHIndependent. Sourced. Local.
BAYOUBREACH
Menu
Back to incident explorer
INCIDENT BRIEF / LAW ENFORCEMENT

Orleans Parish Sheriff's Office

Confirmed incidentNew Orleans, LouisianaSep 4, 2025

A ransomware attack compromised computers at the Orleans Parish Sheriff's Office. Officials initially said jail security computers were unaffected. Later reporting documented prolonged loss of access to the public criminal case lookup tool, while Qilin claimed responsibility for the attack.

01 / OPERATIONAL IMPACT

What happened to the community?

More than a dozen computers were compromised, according to the agency. September 16 reporting said Docket Master had been unavailable for over ten days. The cited reports do not establish that jail security systems were disabled.

Recovery & current status

Not assessed as of today. Source statements concern September 2025.

02 / THE TIMELINE

What the sources document

  1. The sheriff’s office reported ransomware affecting administrative computers; officials said jail security computers were not compromised.

  2. Reporting described continued Docket Master disruption and a Qilin claim of responsibility.

03 / EVIDENCE & ATTRIBUTION

What is known. What is claimed.

Attacker claim reported by journalists; independent official attribution not established in these sources. The group claimed the attack in a September 13 dark-web post and published documents, according to a reporter who reviewed a screenshot. Treat claimed theft totals separately from verified agency impact.

Incident confirmation and attacker attribution are separate questions. A confirmed disruption does not independently verify every claim about stolen data, ransom demands, or responsibility.

CONNECTED INTELLIGENCE

The provider record.

Source: Ransomware.live · Last successful check Oct 9, 2026

These are provider-recorded allegations, not independent findings about the attacker or stolen data. Dates below show when the provider observed a listing.

Attacker claim · unverified

Orleans Parish Sheriff's Office

Ransomware.live records a listing attributed to qilin, observed Sep 14, 2025. Bayou Breach has not independently verified the group’s allegations.

RELATED HISTORICAL BRIEFConfirmed incident

A ransomware attack compromised computers at the Orleans Parish Sheriff's Office. Officials initially said jail security computers were unaffected. Later reporting documented prolonged loss of access to the public criminal case lookup tool, while Qilin claimed responsibility for the attack.

An organization match alone does not establish that this listing describes the same event.

Government Technology: read the reporting
Law enforcement · Orleans Parish
Security gap · FortiReconExact workbook listing match · RL-10708How the technology could help

Matched against a reviewed Louisiana organization directory. This is a limited supplementary source watch, not a statewide census. A scheduled task checks every hour, including while the site is closed. Visits can also refresh a stale snapshot, with at most one refresh attempt per clock hour. No raw-data feed is offered.

04 / FROM INCIDENT TO PREPAREDNESS

Security gap

What to examine in your own environment, and how Fortinet technology could help prevent or limit a similar attack.

Workbook match

Exposure visibility and endpoint containment

The agency acknowledged compromised administrative computers and reporting documented disruption to Docket Master. The workbook supplies a Qilin listing with little technical detail.

What remains unknown: The entry point and scope of any copied data are not established. The claim does not show which security tools were in place or failed.

Read the incident evidence
RECOMMENDED FORTINET PRODUCT · WORKBOOK

FortiRecon

Exposure discovery and adversary intelligence
Cloud service (SaaS)

Subscription exposure-management and intelligence service; not a physical network appliance.

Why it fits: The workbook starts with exposure intelligence because the listing leaves the attack path unknown. A team could investigate relevant external assets and credential alerts, then fix validated exposures.

How the technology works: Continuously discovers exposed assets and prioritizes vulnerabilities, while monitoring leaked credentials, ransomware activity, and other adversary intelligence so teams can remediate exposure and investigate emerging risk before or during an incident.

For it to help: Findings require investigation and remediation; exposure monitoring and ransomware intelligence do not directly block ransomware execution.

Before choosing a model or license
  • Which domains, IP ranges, brands, and vendors are in scope?
  • Who validates and acts on findings?

Choose the capacity and license after reviewing these requirements. This brief does not prescribe an appliance model or promise a historical attack would have been prevented.

Additional controls to validate 3 conditional options
CONDITIONAL FOLLOW-ON

FortiEDR

Endpoint prevention, containment, and response
Endpoint software with cloud or on-premises management

Software agents protect supported endpoints and servers; management components can be cloud, on-premises, or hybrid. This is not an inline hardware firewall.

Why it fits: For a similar ransomware event, behavior-based blocking and device isolation could limit damage on covered administrative computers. This does not establish the original entry point.

How the technology works: An endpoint agent analyzes malware and suspicious process behavior, can block harmful file access and outbound communications, and supports automated isolation and remediation to limit ransomware damage on protected devices.

For it to help: Protection depends on supported devices running the agent with suitable prevention and response policies; this does not guarantee every ransomware attack is stopped.

CONDITIONAL FOLLOW-ON

FortiAuthenticator + FortiToken

Stronger authentication and centralized identity policy
Hardware or virtual identity server + mobile or hardware tokens

FortiAuthenticator is available as a physical or virtual appliance, including private/public-cloud deployment. FortiToken factors include mobile software and hardware tokens or security keys.

Why it fits: Relevant if a review identifies exposed login paths or weak authentication. A stolen-password scenario is not established by the Qilin claim.

How the technology works: Centralizes authentication for integrated applications, VPNs, and administrative access, adding FortiToken factors and identity policies so a stolen password alone is less likely to provide access to protected resources.

For it to help: Phishing resistance requires an appropriate FIDO2 flow; OTP or push alone is not equivalent. Enabling MFA does not establish revocation of already stolen application sessions.

CONDITIONAL FOLLOW-ON

FortiDLP

Sensitive data movement and egress controls
Cloud platform with endpoint agents

Cloud-native data-protection platform using endpoint agents and supported cloud integrations; not a universal inline appliance for all server traffic.

Why it fits: Consider only after identifying sensitive justice records and the actual routes through which they could leave covered systems.

How the technology works: Inspects sensitive data and user activity through endpoint agents and supported cloud integrations, using content, origin, and behavioral context to flag risky movement and enforce controls on covered egress paths.

For it to help: Coverage follows deployed agents and supported integrations or egress paths; it is not universal exfiltration blocking for arbitrary servers or unseen traffic.

ASK YOUR IT TEAM OR SERVICE PROVIDER

Can your team demonstrate endpoint coverage and an approved isolation workflow for the computers that support public case access?

Request conversation
Mapping & assessment notes

Prepared using Five_State_Ransomware_Fortinet_Positioning.xlsx, October 8, 2026 snapshot.

Louisiana account row 20; listing evidence row 51; evidence ID RL-10708. The lead product and conditional follow-ons follow that account row. FortiToken is explained alongside FortiAuthenticator using current vendor documentation.

The workbook’s provider permalink identifies the matching listing. An API match requires that exact record ID and the reviewed organization, not a shared attacker name.

Workbook’s provider record

These are present-day control examples, reviewed October 9, 2026. “Security gap” means an area to evaluate, not a proven failure at the named organization. Products, configurations, historical availability and the actual attack path vary. No product is asserted to have certainly prevented this incident.

How we assess control fit
05 / READ THE ORIGINALS

Sources & further reading