DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Oregon DMV, Louisiana OMV warn residents of MOVEit data breach

Posted on June 16, 2023 by Dissent

Both the Oregon and Louisiana departments of motor vehicles have become victims of the MOVEit hack and millions of drivers and vehicle owners have had their personal information stolen.

Onur Demirkol reports that the Oregon DMV fell prey to the MOVEit hack:

An estimated 3.5 million driver’s license and identity card details were exposed when the organization was hacked two weeks ago, the Oregon Driver and Motor Vehicle Services stated on Thursday. The Oregon DMV data breach might be dangerous for many as they have lost their personal information to possible bad actors. If you are one of them, better contact authorities for an official answer.

The reporter’s recommendation to contact the authorities is somewhat contradicted by the state, though. In a notice by the state, they say, in part:

We do not have the ability to identify if any specific individual’s data has been breached. Individuals who have an active Oregon ID or driver’s license should assume information related to that ID is part of this breach. We recommend individuals take precautionary measures to protect themselves from misuse of this information, such as accessing and monitoring personal credit reports.

The state’s full notice can be found here. It does not list all the data types that may have been accessed or acquired.

Under Oregon law, some driver information is actually a public record — like an Oregonian’s name, address, phone number, and driver’s record.  And under Oregon law, the state can, and actually does, sell that information to certain types of entities. So could criminals set up a fake private investigation service to buy data from the state that could be used in conjunction with the data that has been hacked?   Yes, and hopefully the states will be extra diligent about checking the credentials of any entities that apply to purchase public records data, but even without that data, this is a breach where data may be misused.

Louisiana has also been affected by the breach. The Louisiana Office of Motor Vehicles (OMV) issued a press release that says, in part:

There is no indication at this time that cyber attackers who breached MOVEit have sold, used, shared or released the OMV data obtained from the MOVEit attack. The cyber attackers have not contacted state government. But all Louisianans should take immediate steps to safeguard their identity.

OMV believes that all Louisianans with a state-issued driver’s license, ID, or car registration have likely had the following data exposed to the cyber attackers:

  • Name
  • Address
  • Social Security Number
  • Birthdate
  • Height
  • Eye Color
  • Driver’s License Number
  • Vehicle Registration Information
  • Handicap Placard Information

Gov. John Bel Edwards met with the Unified Command Group at 11 a.m. Thursday to be briefed on the incident, where he instructed the Governor’s Office of Homeland Security and Emergency Preparedness (GOHSEP), Office of Motor Vehicles (OMV), Louisiana State Police (LSP), and the Office of Technology Services (OTS) to act to inform Louisianans of the breach and their best next steps as soon as possible.

Read more of the press release and recommendations at Louisiana’s Warned of Data Leak from Office of Motor Vehicles.

Update: Louisiana believes about 6 million driver’s license and other OMV records were involved.

Category: Government SectorHackU.S.

Post navigation

← Energy Department and other federal agencies affected by MOVEit breach
Detained for DDoS attacks as part of the next edition of the international “Power Off” operation →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.