CSIDB logo
Incident

St. George Fire Protection District

Incident posture

Attack window
Dec 2023
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-09-07 13:12

Linked entities

Victim
St. George Fire Protection District
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2023
Discovered
Dec 2023
Disclosed
May 2026
Resolved
Pending

Summary

A contracted cybersecurity firm allegedly failed to prevent a major breach of the St. George Fire Protection District's network, prompting a lawsuit seeking damages for the intrusion. Attackers used legitimate network tools to evade detection in a "living off the land" attack that compromised domain controllers and gave attackers potential control over the entire network. The same hackers subsequently breached another East Baton Rouge municipal emergency-services agency that shared the firm's services, after the firm reportedly continued using compromised remote-access credentials across clients even after being warned by law enforcement. Following the incident, the district was forced to completely rebuild its network infrastructure, including servers, switches, firewalls, and backups, while the firm allegedly billed the district for remediation work and its own legal fees.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In December 2023, the St. George Fire Protection District, a Louisiana-based emergency services agency, fell victim to a significant cybersecurity breach that ultimately required the complete rebuild of its network infrastructure. The incident was first reported to the fire district by law enforcement on December 23, 2023, when agents informed district officials that their network had been compromised. Following this notification, law enforcement personnel reviewed the fire district's servers to determine how the attackers had gained access. Investigators discovered that the network's domain controllers had been breached. Domain controllers are servers responsible for managing network security, authenticating users, and authorizing access to resources within a domain. Once these central servers are compromised, attackers can potentially access any portion of the network while posing as legitimate, authorized users, effectively bypassing all security controls.

The attackers employed a technique known as "living off the land" to carry out and maintain their intrusion. This method involves using legitimate, trusted software tools already built into the network to evade detection and move laterally through systems. By hijacking these native tools, the adversaries were able to escalate privileges, access different systems and networks, and advance their attack path without raising immediate suspicion. According to the lawsuit subsequently filed by the fire district, the hackers appeared to be positioning themselves within the network for a future attack, likely intended to lock the district out of its own systems. The district's attorneys suspected the ultimate goal was to prevent the fire district from responding to emergencies until a ransom was paid to regain access to the network. The lawsuit also raised concerns that the attackers could have leveraged their trusted position within the fire district's network to gain access to other state or municipal networks connected through shared infrastructure.

Law enforcement investigation revealed that the same group of hackers had breached another East Baton Rouge municipal agency tasked with coordinating emergency services between the parish and St. George through computer-aided dispatch systems. While this second victim was not named in the filing, it was reportedly also a client of General Informatics, the Baton Rouge-based cybersecurity firm contracted by St. George Fire Protection District. A critical security failure was uncovered during the investigation: General Informatics had allegedly been using the same username and password for its remote access tool across its entire client base. According to the lawsuit, law enforcement informed General Informatics in November 2023 that its remote access tool credentials had been compromised, yet the firm continued to use these known compromised credentials when serving other clients, including the fire district. This practice directly contributed to the vulnerability of St. George Fire Protection District's network.

Following the discovery of the breach, the fire district accepted assistance from Louisiana Emergency Support Function-17, a subsection of the Governor's Office of Homeland Security and Environmental Protection. This agency conducted a comprehensive five-month review of the fire district's network security, uncovering multiple additional vulnerabilities beyond the initial compromise. Among the most concerning findings was a note written in plain text that contained the fire district's administrative credentials for its various accounts and software applications, essentially providing anyone with network access the keys to the entire system. The review also determined that the network's firewall was not recording logging activity, eliminating the ability to track potential security events. Furthermore, the network was not segmented, meaning there were no internal controls to prevent the spread of malware or unauthorized access between different parts of the system. Additional findings revealed that General Informatics had allegedly installed high-speed internet for the fire district at the district's expense, but then sold the fire district network switches that were incapable of accommodating the new high-speed fiber internet. The lawsuit further claimed that General Informatics never made any backups of the fire district's servers, despite this being a contractual requirement.

As a direct consequence of the attack and the numerous security vulnerabilities identified, the St. George Fire Protection District was forced to undertake a complete rebuild of its entire network. This extensive remediation effort included acquiring new servers, new switches, new domain controllers, new firewalls, and implementing new backup systems. In a further development, General Informatics subsequently billed the fire district for the server remediation efforts and for the firm's own legal expenses. On May 23, 2026, the fire district filed a lawsuit against General Informatics seeking damages for the December 2023 security breach, alleging that the contracted cybersecurity firm had failed to prevent the attack and had left the district "imminently vulnerable to a cyber-attack." In response to the suit, General Informatics filed a motion on May 18 to force the dispute into arbitration rather than proceeding through the court system.

Sources

Sources available to members: 1 source.

CSIDB