Oregon and Louisiana: Millions of state IDs stolen in MOVEit breach.
Louisiana and Oregon warned that millions of driver's licenses were exposed to a data breach after a ransomware gang breached MOVEit Transfer's secure file transfer systems, stealing stored data.
These attacks were carried out by the Clop ransomware operation, which launched global attacks on MOVEit Transfer servers on May 27 using a previously unknown zero-day vulnerability identified as CVE-2023-34362.
These attacks have led to widespread disclosures of data breaches worldwide, impacting companies, federal, state, and local government agencies.
According to press releases from the Louisiana Bureau of Motor Vehicles and Oregon Driver & Motor Vehicle Services, both agencies used MOVEit Transfer software, which was compromised during these attacks.
See also: Skuld malware: Steals Discord and Browser data from Windows PCs

See also: LockBit ransomware: Suspected collaborator from Russia arrested
Millions of driver's licenses stolen
The Louisiana Office of Motor Vehicles (OMV) announced yesterday that it believes all Louisiana residents who have state-issued driver's licenses, ID cards or car registrations have likely had data to threat actors.
OMV stated that those affected potentially had the following personal information exposed:
- Name
- Address
- Social Security Number
- Date of birth
- Height
- Eye color
- Driving license number
- Vehicle registration information
However, the organization says there is no indication that the Clop group used, sold, shared, or released any of this data; therefore, the stolen data may have been deleted, as the ransomware perpetrators promised in their announcement that they would delete all stolen government data.
However, millions of people living in Louisiana should consider their data at risk - we advise them to take appropriate steps to protect their identities, reset their passwords, freeze their bank accounts, and report any suspicious activity to authorities and their card issuers.
The Oregon DMV issued a similar statement and press release explaining that the MOVEit Transfer data breach affected approximately 3.5 million Oregon residents with an ID or driver's license.
Oregon authorities said they are unable to identify specific victims, so all citizens are advised to assume that their personal data has been exposed to cybercriminals.
While Clop began blackmailing victims of the MOVEit attacks on Wednesday, listing the companies that have been hacked on the ransomware firm's data leak website, no stolen data has yet been leaked.
Furthermore, since both the Louisiana and Oregon DMVs fall under the government category, it's too early to tell whether the Clop hackers will keep their promise and delete the stolen data.
See also: BlackCat ransomware: Hackers threaten to leak Reddit data
Even if this data is never used in extortion attempts, it is possible that the data will be sold to other threat actors.
Other organizations that have already disclosed MOVEit Transfer breaches include US federal agencies, Zellis (BBC, Boots and Aer Lingus, Ireland's HSE via Zellis), the University of Rochester, the Government of Nova Scotia, the US state of Missouri, the US state of Illinois, BORN Ontario, Ofcam, Extreme Networks and the American Board of Internal Medicine.
Information source: bleepingcomputer.com
