Hacking/IT Incident
LHC GroupHHS lists Hacking/IT Incident involving Network Server. Reporting category: Healthcare Provider. This is a submitted notice, not a finding about the attacker or cause.
BAYOUBREACHConnect threat-intelligence listings to local reporting and practical security questions. An attacker’s allegation is a lead, and independent evidence determines what we can say about the incident.
Official notices, reporting leads and technical context for reviewed Louisiana organizations. These records do not change the curated incident count.
Incident-related headlines matched to reviewed organizations.
Source rate limit reached. The last successful snapshot is retained.
Public HHS export: cases currently under investigation, generally reports affecting 500 or more people in the last 24 months. Six organization identities are reviewed. Submission dates are not attack dates.
Recent 8-K / 8-K/A Item 1.05 filings from five reviewed Louisiana-connected energy and communications operators. Historical filing archives and generic risk disclosures are not included.
Public breach catalog only. No email-address searches, account exposure queries or personal datasets.
Only CVEs explicitly connected to a curated incident are shown. KEV is vulnerability context, not a count of local attacks or evidence of a current agency weakness.
Daily scores joined only to explicitly referenced CVEs. Missing values are not displayed as zero.
Pending a read-only Radar token and reviewed network-to-organization mappings. No outage data is being published.
HHS lists Hacking/IT Incident involving Network Server. Reporting category: Healthcare Provider. This is a submitted notice, not a finding about the attacker or cause.
HHS lists Hacking/IT Incident involving Network Server. Reporting category: Healthcare Provider. This is a submitted notice, not a finding about the attacker or cause.
HHS lists Hacking/IT Incident involving Email. Reporting category: Healthcare Provider. This is a submitted notice, not a finding about the attacker or cause.
HHS lists Hacking/IT Incident involving Network Server. Reporting category: Healthcare Provider. This is a submitted notice, not a finding about the attacker or cause.
HHS lists Unauthorized Access/Disclosure involving Network Server, Other. Reporting category: Health Plan. This is a submitted notice, not a finding about the attacker or cause.
HHS lists Unauthorized Access/Disclosure involving Email. Reporting category: Business Associate. This is a submitted notice, not a finding about the attacker or cause.
HHS totals refer to the full submitted report. SEC notices may concern a company’s operations outside Louisiana. News leads require review. Technical forecasts describe vulnerabilities, not an organization’s current risk. How sources are filtered
These public sources support organization identity, Louisiana presence and sector eligibility. They do not confirm a breach. New source notices remain separate from the curated incident archive.
These are provider-recorded allegations, not independent findings about the attacker or stolen data. Dates below show when the provider observed a listing.
Ransomware.live records a listing attributed to qilin, observed Sep 14, 2025. Bayou Breach has not independently verified the group’s allegations.
A ransomware attack compromised computers at the Orleans Parish Sheriff's Office. Officials initially said jail security computers were unaffected. Later reporting documented prolonged loss of access to the public criminal case lookup tool, while Qilin claimed responsibility for the attack.
An organization match alone does not establish that this listing describes the same event.
Government Technology: read the reportingRansomware.live records a listing attributed to rhysida, observed Nov 27, 2024. Bayou Breach has not independently verified the group’s allegations.
Vermilion schools took networks offline while investigating a potential compromise on October 7, 2024. Rhysida later claimed stolen data. Reporting explicitly said the district had not verified the group's claim.
An organization match alone does not establish that this listing describes the same event.
Comparitech: read the reportingRansomware.live records a listing attributed to conti, observed Sep 1, 2020. Bayou Breach has not independently verified the group’s allegations.
Security reporting described Conti publishing purported court documents and the court website going offline. No court confirmation was located. This is Louisiana's state trial court serving Ouachita and Morehouse parishes.
An organization match alone does not establish that this listing describes the same event.
Dark Reading: read the reportingRansomware.live records a listing attributed to ryuk, observed Nov 18, 2019. Bayou Breach has not independently verified the group’s allegations.
Louisiana officials shut down state servers after detecting ransomware on November 18, 2019. Websites, email and online services were interrupted. StateScoop reported Ryuk malware; an official notice documented billing disruption.
An organization match alone does not establish that this listing describes the same event.
StateScoop: read the reportingMatched against a reviewed Louisiana organization directory. This is a limited supplementary source watch, not a statewide census. A scheduled task checks every hour, including while the site is closed. Visits can also refresh a stale snapshot, with at most one refresh attempt per clock hour. No raw-data feed is offered.
The connected search currently reviews 4 Louisiana organizations. The broader incident archive includes additional manually researched records. A missing listing does not mean an organization is unaffected.
New organizations and incident confirmations require editorial review. Matched official notices and headlines appear separately in the source watch. The site retains the last successful snapshot if the provider is unavailable. A new listing does not automatically receive a product recommendation.
Read the update methodCurated follow-ups add service impacts, official statements and exposure findings. These are publication dates; editorial review was October 9, 2026.
Terrebonne Parish took systems offline after discovering suspicious activity on September 30. An October 5 update said restoration was continuing while essential government operations remained available. The identity of any attacker, ransomware involvement and data-loss scope were not established.
What this adds: New 2026 public-sector case; dated follow-up distinguishes continued essential operations from incomplete systems restoration.
EBRSO initially described a quickly contained intrusion with limited data loss. In August 2025, Straight Arrow News reported reviewing a much larger leaked collection containing sensitive investigative records. This follow-up materially expands the documented exposure beyond the initial agency account.
What this adds: August 4, 2025 investigation reports examination of the leaked dataset and challenges the initial characterization of limited exposure.
Acadian confirmed unauthorized network access during June 19–21, 2024, potentially exposing patient identifiers and medical information. Later reporting placed the notified population near 2.9 million. A May 2025 report described litigation over the breach and Acadian's request for dismissal.
What this adds: May 2, 2025 litigation follow-up provides a dated consequence beyond the original listing. Use the official June access window, despite news shorthand calling this a July breach.
Bring the incident, the evidence and one specific question about your own environment.