Frequently Asked Questions

What happened?

A third-party software product called MOVEit File Transfer System experienced a “Zero-Day Vulnerability” exploited by bad actors. It is anticipated that a significant number of entities, both public and private, that utilized MOVEit were impacted. After a thorough digital forensic analysis, it was determined that the bad actors had access to Office of Motor Vehicles (OMV) files within one MOVEit server containing the records of Louisiana citizens. However, current intelligence indicates that data belonging to state governments, including that of Louisiana, was not the intended target.


What is a Zero-Day Vulnerability?

A “Zero-Day Vulnerability” is a defect that renders a technology product vulnerable to bad actors that is discovered, and often exploited, before the product's manufacturer can remedy the vulnerability. Until the manufacturer can issue a remedy, bad actors can exploit it to their advantage. More information on the MOVEit Zero-Day Vulnerability can be found online with the Cybersecurity and InfrastructureSecurity Agency.


What is the MOVEit File Transfer Software?

MOVEit enables its customers to transfer an extremely large volume of files organizations or components of an organization. More information about MOVEit's capabilities can be found here.


Are any state services currently suspended or planned on being suspended in response to the MOVEit Software vulnerability?

No state services have been suspended because of the MOVEit software vulnerability, and there are no current plans to suspend any of those services.


Was LaWallet affected by this incident?

There is no indication or evidence that LaWallet was impacted by this incident.


How quickly did the State respond to learning about the MOVEit Software vulnerability?

MOVEit's manufacturer sent notification of a Zero-Day Vulnerability exploited by bad actors on May 31, 2023, in a blanket statement to its global list of customers. However, this statement only alerted customers to the problem with the software itself. This message did NOT inform MOVEit customers of the scope or severity of the potential impact to each customer's individual systems or data files.

The state's cyber incident response team, including officials from the Office of Technology Services (OTS), Louisiana State Police (LSP), and the Governor's Office of Homeland Security and Emergency Preparedness (GOHSEP) immediately initiated response procedures and an intensive digital forensic investigation.

It was June 2nd when MOVEit's manufacturer announced a software patch to cure the vulnerability, which the state immediately implemented.

During the evening of June 14th, the state of Louisiana completed its review of potentially impacted files, and identified certain records for Louisiana residents that applied for and/or received drivers' licenses, identification cards, and vehicle registrations.

On June 15th, Governor John Bel Edwards received a briefing from GOHSEP, LSP, OTS, and OMV. Governor Edwards immediately directed GOHSEP to notify public of the possible exposure of sensitive data. The next morning, a media briefing was held and a press release was issued with available details about the breach and protective measures for the public to take. At this time, no other servers have been identified as compromised by the bad actors.


Can the state provide free credit monitoring?

The state is considering all available resources to help its citizens. Credit monitoring is a top priority and more information on this will be published on NextSteps.la.gov as soon as possible.


Who should you contact if you have questions or concerns?

At a minimum, the correct points of contact for any citizen suspecting abnormal activity will include the following:

  1. The issuer of the credit card, loan, or financial service that reported the activity, which may also be a government agency
  2. The Federal Trade Commission at IdentityTheft.gov
  3. The Social Security Administration at ssa.gov
  4. All three credit monitoring agencies (See contact information on NextSteps.la.gov)
  5. The Louisiana Attorney General's Office - Consumer Protection Division at 1-800-351-4889

Is the investigation complete?

The investigation remains ongoing into both the scope and impact of the vulnerability. State and federal authorities are actively monitoring dark web activity by the group of bad actors claiming responsibility for this event. The Office of Technology Services (OTS) is also monitoring other state agencies to ensure that no other data was potentially impacted.


Who was responsible for this incident?

According to the Cybersecurity and Infrastructure Security Agency (CISA), CL0p Ransomware Group is claiming responsibility for the incident. More information from CISA about CL0p and this incident can be found here.


Could the state have done more to avoid this issue?

This was a Zero-Day Vulnerability. This means that the attackers found a defect with a third-party software product before its manufacturer or other sophisticated cybersecurity professionals became aware. Unfortunately, the state of Louisiana, along with countless other entities, both public and private, were impacted by simply being MOVEit customers.


Was the state using outdated or “end-of-life” versions of MOVEit?

The Office of Motor Vehicles (OMV) was utilizing version 14.0.4 of MOVEit at the time of the breach. It was released in May of this year and was the most recent patch available for the software at the time.

The MOVEit Software has different versions that it consistently maintains and patches. According to MOVEit's manufacturer, all versions of MOVEit were exploitable by the same Zero-Day Vulnerability. Any contention that the state's version of the software was too old or that its specific versions increased vulnerability to this new Zero-Day Vulnerability is simply incorrect. None of the versions of MOVEit's File Transfer Software were impervious to this incident as this type of breach is distinctly unpredictable and able to be exploited before the targeted manufacturer is made aware of the event. For more information, please see: https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023.


Will the state do anything different to increase the protection of data?

Our state and federal partners are conducting a thorough assessment of the incident and will incorporate all lessons learned into future security measures.


What is the state doing to protect other information from this MOVEit incident?

The state implemented the software patch, as issued by MOVEit's manufacturer, immediately after its release to cure the “Zero-Day Vulnerability.” Additionally, the state implemented certain firewall configurations to defend itself against internet traffic from MOVEit's web services.


What is the role of the federal government in this incident?

CISA issued a Common Vulnerabilities and Exposures (CVE) warning, which the state is closely monitoring. CISA has further advised that it is also contacting private entities that may have been impacted by this vulnerability.


Will the state declare an emergency for this event?

No state declaration of emergency has been issued for this event. However, this is being considered and will be appropriately addressed, if it becomes necessary.


Who is at fault?

This incident was not the result of any act or omission by the state of Louisiana. This was a vulnerability exploited by bad actors of a third-party vendor's software. While the state's foremost priority is protecting its citizens, officials are exploring any available general or legal recourse.


Why is the state advising citizens to change their passwords?

The data that was compromised on the OMV server did not include anyone's personal password. The advice to change passwords is among best practices and is given strictly out of an abundance of caution. For certain systems, personal information can be used to either recover passwords or access accounts. Additionally, some individuals use the same password for multiple accounts. Therefore, this event is an excellent reminder to periodically change passwords every 90 days at a minimum to prevent unauthorized account access. Please also see the following article from NOLA.com.


Will this impact Louisiana elections this year?

The Louisiana Secretary of State's Office, which administers state elections, was not a MOVEit customer and therefore, not impacted by this event.