New Orleans declares state of emergency, shuts down its network after a ransomware attack on Friday, says it had found no signs that data was lost in the attack
New Orleans is the third major American city in roughly two years to be knocked offline by ransomware, following the sustained attack on Atlanta in 2018 and Baltimore, which put its cleanup bill at $10M plus $8M in lost revenue. The difference here is speed of escalation: rather than treating it as an IT incident, the city invoked an emergency declaration and pulled its own network down.
The state-level dimension was already visible in Louisiana — months after this attack, the Louisiana National Guard was called in to help small government offices under repeated cyberattack — so New Orleans' emergency framing fits a pattern the state had already begun institutionalizing.
First-order effects
City employees are working without network systems while Collin Arnold's Office of Homeland Security and Emergency Preparedness runs the response, and the no-data-loss finding keeps the incident in containment mode rather than extortion-negotiation mode.
Second-order effects
Peer cities watching Baltimore's nine-figure combined cost now have a template for declaring emergencies early, shifting ransomware from a CIO budget line to a governor-and-National-Guard response category.
Third-order effects
If the arc from Atlanta through New Orleans to Costa Rica's nationwide emergency holds, municipal ransomware stops being a series of one-off breaches and becomes a standing public-safety function, with state cyber reserves as routine as storm response.
The trend: Ransomware against local government is migrating from an IT crisis handled by city IT departments to a declared emergency drawing state and military-cyber resources.
A declaration of a state of emergency has been filed with the Civil District Court in connection with today's cyber security event. pic.twitter.com/OQXDGv7JS4
Beginning at 5am today, suspicious activity was detected on the City's network. As technicians investigated, activity indicating a cybersecurity incident was detected around 11am and as a precaution, the City's IT department began powering down servers and City computers.
This has GRU-like fingerprints. Check Louisiana's voting machines! Remember Trump has again asked Russia, not just Ukraine, to help him “win” reelection in 2020. Article I charges Trump's compromise of our election integrity and national security . . . https://www.cnn.com/...
What we know: ➡ At least 4,000 computers will need to be scrubbed. ➡ Around 400 servers were affected. ➡ City officials said the attack was “very minimal” https://www.nola.com/...
@tribelaw Prof. Tribe- This incident is completely consistent with other ransomware attacks against municipalities and there is no indication of GRU activity nor is this consistent with known GRU TTPs (Tactics, Techniques and Procedures). I suggest you delete this tweet.
Nothing has surfaced suggesting this is GRU. Yes, they use ransomware, but the threat to state and municipal networks from good old fashioned criminals is far, far greater. https://twitter.com/...
It's true Louisiana uses digital voting machines, but they are never connected to the internet. They're also currently in storage and have nothing to do with what happened Friday: an attack against the city of New Orleans's municipal IT systems. What an irresponsible tweet. https…
#Ransomware attacks are costing taxpayers & it doesn't have to keep happening! Time for State & local governments to start complying with the @NIST standard & use anti-virus software based on whitelisting! @POTUS @pcmatic #CyberSecurity @NISTcyber https://www.forbes.com/...
New Orleans police & EMS have been operating by radio only this afternoon because their computers were affected by the cyberattack on the city (WWL) https://www.wwltv.com/...