LOUISIANA CYBER INCIDENT WATCHIndependent. Sourced. Local.
BAYOUBREACH
Menu
CONNECTED SOURCE WATCH

Track the claim.
Keep the context.

Connect threat-intelligence listings to local reporting and practical security questions. An attacker’s allegation is a lead, and independent evidence determines what we can say about the incident.

Connected evidence snapshot
Last successful API check
Latest refresh attempt
4Provider listingsAllegations, not a count of confirmed attacks
4Exact workbook matchesSame provider record and reviewed organization
1hScheduled refreshRuns while the site is closed; timing may vary
BEYOND RANSOMWARE

More sources. Clearer context.

Official notices, reporting leads and technical context for reviewed Louisiana organizations. These records do not change the curated incident count.

GDELT news discoverySource unavailable · 0 scoped records

Incident-related headlines matched to reviewed organizations.

Source rate limit reached. The last successful snapshot is retained.

Last successful check
No successful check yet
Check cadence
Hourly
Source & documentation
HHS breach noticesConnected · 6 scoped records

Public HHS export: cases currently under investigation, generally reports affecting 500 or more people in the last 24 months. Six organization identities are reviewed. Submission dates are not attack dates.

Last successful check
Oct 9, 3:24 PM UTC
Check cadence
Daily
Source & documentation
SEC cyber disclosuresConnected · 0 scoped records

Recent 8-K / 8-K/A Item 1.05 filings from five reviewed Louisiana-connected energy and communications operators. Historical filing archives and generic risk disclosures are not included.

Last successful check
Oct 9, 3:24 PM UTC
Check cadence
Hourly
Source & documentation
Have I Been PwnedConnected · 0 scoped records

Public breach catalog only. No email-address searches, account exposure queries or personal datasets.

Last successful check
Oct 9, 3:24 PM UTC
Check cadence
Daily
Source & documentation
CISA known exploited vulnerabilitiesConnected · 1 scoped records

Only CVEs explicitly connected to a curated incident are shown. KEV is vulnerability context, not a count of local attacks or evidence of a current agency weakness.

Last successful check
Oct 9, 3:24 PM UTC
Check cadence
Daily
Source & documentation
FIRST EPSSConnected · 1 scoped records

Daily scores joined only to explicitly referenced CVEs. Missing values are not displayed as zero.

Last successful check
Oct 9, 3:24 PM UTC
Check cadence
Daily
Source & documentation
Cloudflare RadarSetup pending · 0 scoped records

Pending a read-only Radar token and reviewed network-to-organization mappings. No outage data is being published.

Last successful check
No successful check yet
Check cadence
Hourly
Source & documentation
6 records
Official health noticeReported to HHS · Sep 4, 2026

Hacking/IT Incident

LHC Group

HHS lists Hacking/IT Incident involving Network Server. Reporting category: Healthcare Provider. This is a submitted notice, not a finding about the attacker or cause.

500Individuals in the HHS report, not a Louisiana resident count
Healthcare · Louisiana healthcare organization; Lafayette
U.S. Department of Health and Human Services, Office for Civil Rights
Official health noticeReported to HHS · Dec 9, 2025

Hacking/IT Incident

Ochsner LSU Health – Regional Urology

HHS lists Hacking/IT Incident involving Network Server. Reporting category: Healthcare Provider. This is a submitted notice, not a finding about the attacker or cause.

4,519Individuals in the HHS report, not a Louisiana resident count
Healthcare · Louisiana healthcare organization; Shreveport
U.S. Department of Health and Human Services, Office for Civil Rights
Official health noticeReported to HHS · Sep 2, 2025

Hacking/IT Incident

North Oaks Health System

HHS lists Hacking/IT Incident involving Email. Reporting category: Healthcare Provider. This is a submitted notice, not a finding about the attacker or cause.

6,243Individuals in the HHS report, not a Louisiana resident count
Healthcare · Public hospital service district; Hammond
U.S. Department of Health and Human Services, Office for Civil Rights
Official health noticeReported to HHS · May 6, 2025

Hacking/IT Incident

The Carpenter Health Network

HHS lists Hacking/IT Incident involving Network Server. Reporting category: Healthcare Provider. This is a submitted notice, not a finding about the attacker or cause.

878Individuals in the HHS report, not a Louisiana resident count
Healthcare · Louisiana healthcare organization; Baton Rouge
U.S. Department of Health and Human Services, Office for Civil Rights
Official health noticeReported to HHS · Mar 21, 2025

Unauthorized Access/Disclosure

AmeriHealth Caritas Louisiana

HHS lists Unauthorized Access/Disclosure involving Network Server, Other. Reporting category: Health Plan. This is a submitted notice, not a finding about the attacker or cause.

1,552Individuals in the HHS report, not a Louisiana resident count
Healthcare · Louisiana healthcare organization; Baton Rouge
U.S. Department of Health and Human Services, Office for Civil Rights
Official health noticeReported to HHS · Feb 14, 2025

Unauthorized Access/Disclosure

RestorixHealth

HHS lists Unauthorized Access/Disclosure involving Email. Reporting category: Business Associate. This is a submitted notice, not a finding about the attacker or cause.

38,553Individuals in the HHS report, not a Louisiana resident count
Healthcare · Louisiana healthcare organization; Metairie
U.S. Department of Health and Human Services, Office for Civil Rights

HHS totals refer to the full submitted report. SEC notices may concern a company’s operations outside Louisiana. News leads require review. Technical forecasts describe vulnerabilities, not an organization’s current risk. How sources are filtered

Why an organization qualifies · 24 reviewed identities

These public sources support organization identity, Louisiana presence and sector eligibility. They do not confirm a breach. New source notices remain separate from the curated incident archive.

Terrebonne Parish Consolidated Government Local government · Louisiana public entityLouisiana scope evidenceAcadian Ambulance Service, Inc. Healthcare · Louisiana critical-infrastructure providerLouisiana scope evidenceEast Baton Rouge Parish Sheriff's Office Law enforcement · Louisiana public entityLouisiana scope evidenceOrleans Parish Sheriff's Office Law enforcement · Louisiana public entityLouisiana scope evidenceVermilion Parish School System Education · Louisiana public entityLouisiana scope evidenceSt. Landry Parish School Board Education · Louisiana public entityLouisiana scope evidenceLouisiana Office of Motor Vehicles State government · Louisiana public entityLouisiana scope evidenceSoutheastern Louisiana University Education · Louisiana public entityLouisiana scope evidenceLake Charles Memorial Health System Healthcare · Louisiana critical-infrastructure providerLouisiana scope evidenceBaton Rouge General / General Health System Healthcare · Louisiana critical-infrastructure providerLouisiana scope evidenceFourth Judicial District Court of Louisiana Courts · Louisiana public entityLouisiana scope evidenceCity of New Orleans Local government · Louisiana public entityLouisiana scope evidenceLouisiana Office of Technology Services / State of Louisiana State government · Louisiana public entityLouisiana scope evidenceEntergy Corporation Energy & utilities · Louisiana-serving infrastructure operatorLouisiana scope evidenceLumen Technologies, Inc. Communications · Louisiana-serving infrastructure operatorLouisiana scope evidenceCleco Corporate Holdings LLC Energy & utilities · Louisiana-serving infrastructure operatorLouisiana scope evidenceCleco Power LLC Energy & utilities · Louisiana electric utilityLouisiana scope evidenceAtmos Energy Corporation Energy & utilities · Louisiana-serving infrastructure operatorLouisiana scope evidenceLHC Group Healthcare · Louisiana healthcare organization; LafayetteLouisiana scope evidenceOchsner LSU Health – Regional Urology Healthcare · Louisiana healthcare organization; ShreveportLouisiana scope evidenceNorth Oaks Health System Healthcare · Public hospital service district; HammondLouisiana scope evidenceThe Carpenter Health Network Healthcare · Louisiana healthcare organization; Baton RougeLouisiana scope evidenceAmeriHealth Caritas Louisiana Healthcare · Louisiana healthcare organization; Baton RougeLouisiana scope evidenceRestorixHealth Healthcare · Louisiana healthcare organization; MetairieLouisiana scope evidence
CONNECTED INTELLIGENCE

Claims in context.

Source: Ransomware.live · Last successful check Oct 9, 2026

These are provider-recorded allegations, not independent findings about the attacker or stolen data. Dates below show when the provider observed a listing.

Attacker claim · unverified

Orleans Parish Sheriff's Office

Ransomware.live records a listing attributed to qilin, observed Sep 14, 2025. Bayou Breach has not independently verified the group’s allegations.

RELATED HISTORICAL BRIEFConfirmed incident

A ransomware attack compromised computers at the Orleans Parish Sheriff's Office. Officials initially said jail security computers were unaffected. Later reporting documented prolonged loss of access to the public criminal case lookup tool, while Qilin claimed responsibility for the attack.

An organization match alone does not establish that this listing describes the same event.

Government Technology: read the reporting
Law enforcement · Orleans Parish
Security gap · FortiReconExact workbook listing match · RL-10708How the technology could help
Read the historical brief View provider record
Attacker claim · unverified

Vermilion Parish School System

Ransomware.live records a listing attributed to rhysida, observed Nov 27, 2024. Bayou Breach has not independently verified the group’s allegations.

RELATED HISTORICAL BRIEFReported incident

Vermilion schools took networks offline while investigating a potential compromise on October 7, 2024. Rhysida later claimed stolen data. Reporting explicitly said the district had not verified the group's claim.

An organization match alone does not establish that this listing describes the same event.

Comparitech: read the reporting
Education · Vermilion Parish
Security gap · FortiReconExact workbook listing match · RL-16892How the technology could help
Read the historical brief View provider record
Attacker claim · unverified

Fourth Judicial District Court

Ransomware.live records a listing attributed to conti, observed Sep 1, 2020. Bayou Breach has not independently verified the group’s allegations.

RELATED HISTORICAL BRIEFUnverified claim

Security reporting described Conti publishing purported court documents and the court website going offline. No court confirmation was located. This is Louisiana's state trial court serving Ouachita and Morehouse parishes.

An organization match alone does not establish that this listing describes the same event.

Dark Reading: read the reporting
Courts · Ouachita / Morehouse Parish
Security gap · FortiReconExact workbook listing match · RL-32225How the technology could help
Read the historical brief View provider record
Attacker claim · unverified

Louisiana Office of Technology Services

Ransomware.live records a listing attributed to ryuk, observed Nov 18, 2019. Bayou Breach has not independently verified the group’s allegations.

RELATED HISTORICAL BRIEFConfirmed incident

Louisiana officials shut down state servers after detecting ransomware on November 18, 2019. Websites, email and online services were interrupted. StateScoop reported Ryuk malware; an official notice documented billing disruption.

An organization match alone does not establish that this listing describes the same event.

StateScoop: read the reporting
State government · Statewide
Security gap · FortiEDRExact workbook listing match · RL-32404How the technology could help
Read the historical brief View provider record

Matched against a reviewed Louisiana organization directory. This is a limited supplementary source watch, not a statewide census. A scheduled task checks every hour, including while the site is closed. Visits can also refresh a stale snapshot, with at most one refresh attempt per clock hour. No raw-data feed is offered.

WHAT THIS WATCH COVERS

A reviewed directory.
A deliberately limited feed.

The connected search currently reviews 4 Louisiana organizations. The broader incident archive includes additional manually researched records. A missing listing does not mean an organization is unaffected.

New organizations and incident confirmations require editorial review. Matched official notices and headlines appear separately in the source watch. The site retains the last successful snapshot if the provider is unavailable. A new listing does not automatically receive a product recommendation.

Read the update method
INDEPENDENT REPORTING

What the reporting adds.

Curated follow-ups add service impacts, official statements and exposure findings. These are publication dates; editorial review was October 9, 2026.

All sources & reports
The Times of Houma/Thibodaux

Terrebonne Parish Government systems remain offline following cyber security incident

Terrebonne Parish took systems offline after discovering suspicious activity on September 30. An October 5 update said restoration was continuing while essential government operations remained available. The identity of any attacker, ransomware involvement and data-loss scope were not established.

What this adds: New 2026 public-sector case; dated follow-up distinguishes continued essential operations from incomplete systems restoration.

Straight Arrow News

Exclusive: Confidential informants exposed in Louisiana sheriff’s office hack

EBRSO initially described a quickly contained intrusion with limited data loss. In August 2025, Straight Arrow News reported reviewing a much larger leaked collection containing sensitive investigative records. This follow-up materially expands the documented exposure beyond the initial agency account.

What this adds: August 4, 2025 investigation reports examination of the leaked dataset and challenges the initial characterization of limited exposure.

EMS1 / The Advocate

Acadian Ambulance seeks dismissal of data breach lawsuit

Acadian confirmed unauthorized network access during June 19–21, 2024, potentially exposing patient identifiers and medical information. Later reporting placed the notified population near 2.9 million. A May 2025 report described litigation over the breach and Acadian's request for dismissal.

What this adds: May 2, 2025 litigation follow-up provides a dated consequence beyond the original listing. Use the official June access window, despite news shorthand calling this a July breach.

Turn a listing into a useful conversation.

Bring the incident, the evidence and one specific question about your own environment.

Request conversation