Personal data of millions of Americans exposed in global cyber attack — what you need to know

An open lock depicting a data breach
(Image credit: Shutterstock)

Americans from Louisiana and Oregon could be at risk of falling victim to identity theft and other cyberattacks following a massive data breach that occurred last month.

As reported by BleepingComputer, the Clop ransomware gang began exploiting a previously unknown zero-day vulnerability (tracked as CVE-2023-34362) in the popular file transfer software MOVEit Transfer on May 27.

Since this software is used by large companies from a wide variety of industries from finance and education to energy, IT, healthcare and more as well as by government organizations, the impact of this data breach is already being felt worldwide.

Given that the Louisiana Office of Motor Vehicles (OMV) and the Oregon Driver & Motor Vehicles Services both use MOVEit Transfer as part of their operations, Louisiana and Oregon are now warning that millions of driver’s licenses and other state-issued documents have been obtained by the Clop ransomware gang following the attacks from last month.

Unlike with malicious apps or phishing attacks, even if users weren’t taking unnecessary risks online, their personal data is now in the hands of hackers as a result of the MOVEit breach.

State-issued IDs and documents stolen by hackers

A hacker typing quickly on a keyboard

(Image credit: Shutterstock)

In a new alert, Louisiana’s OMV revealed that it believes that everyone who lives in the state and has a state-issued driver’s license, ID or car registration likely had their personal data exposed by Clop.

According to the OMV, the full names, physical addresses, Social Security numbers, birth dates, height, eye color, driver’s license numbers, vehicle registration information and handicap placard information of Louisiana residents was exposed. However, the agency says that so far, there has been no indication that the hackers responsible have used, sold, shared or released any of this stolen data yet.

In fact, the Clop ransomware gang may have actually deleted this data as they promised to erase any stolen government data in an announcement put out following the data breach.

Meanwhile, Oregon’s DMV also released a statement along with a press release in which it explained that approximately 3.5 million Oregonians with an ID or driver's license have been impacted as a result of the MOVEit breach. Unfortunately though, the state’s authorities have said that they are unable to identify specific victims at this time which means that all residents of the state will need to take the necessary precautions and assume that the Clop ransomware gang has their personal data.

How to stay safe if your personal data was exposed in the MOVEit data breach

As of now, the Clop ransomware gang has only revealed which companies and organizations have been affected as the result of the MOVEit data breach on its data leak site. None of the data stolen in the breach has been leaked yet but it could be.

We also don’t know whether or not the group will honor its promise to delete stolen government data. For the moment, we’re going to have to take the hackers behind this massive data breach at their word but there are still precautions you can take if you live in either Louisiana or Oregon.

For starters, you want to operate on the assumption that your data was stolen by the Clop ransomware gang. This means that you will need to monitor your credit reports, bank statements and other financial accounts for signs of identity theft. At the same time, you also want to be on the lookout for targeted phishing attacks that may use this stolen data against you or as a lure to pay the hackers responsible.

If you’ve already signed up for one of the best identity theft protection services, they will be able to help you recover your identity as well as any funds lost to fraud. However, you would have needed to be a paying subscriber before the MOVEit breach occurred to take advantage of these protections.

For now though, we should all be extra careful online regardless of whether or not we live in Louisiana or Oregon as US federal agencies and businesses around the world have been impacted by this massive data breach.

More from Tom's Guide

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Surfshark graphic of 2024 data breaches
Nearly 700 million American records were leaked in 2024
An open lock depicting a data breach
3.5 million hit in major law firm data breach — full names, SSNs, dates of birth, addresses and more exposed
An open lock depicting a data breach
Massive healthcare data breach just exposed the personal info of 1 million Americans — what to do now
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
An open lock depicting a data breach
The top 10 data breaches of 2024
US Capitol building dome with American flag
These states have the worst data privacy in the US – is yours one of them?
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now