CSIDB logo
Incident

New Mexico Regulation and Licensing Department

Incident posture

Attack window
Oct 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-16 00:00

Linked entities

Victim
New Mexico Regulation and Licensing Department
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Unauthorized access to information systems at the New Mexico Regulation and Licensing Department prompted an investigation by the state’s Cybersecurity Office. The incident was isolated and mitigated, with ongoing efforts to assess the situation and ensure security. No specific details regarding the scope or nature of compromised data were disclosed in available reports.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In October 2022, the New Mexico Department of Information Technology’s Cybersecurity Office initiated an investigation into unauthorized access targeting information systems operated by the state’s Regulation and Licensing Department (RLD). The incident came to light on or around October 13, 2022, though the precise timeline of initial intrusion detection and the specific systems involved were not publicly disclosed. State authorities confirmed the Cybersecurity Office assumed primary responsibility for assessing the breach, coordinating with RLD to contain the incident. While technical details regarding the attack vector, duration of unauthorized access, and identity of threat actors remained under investigation, officials stated they had isolated and mitigated the unauthorized access. No immediate evidence suggested widespread compromise of other state agencies, though the full scope of impacted RLD systems or data repositories was not yet determined at the time of initial reporting.

The state’s investigation remained ongoing as of the initial disclosure, with no confirmation regarding whether sensitive data—such as personally identifiable information, licensing records, or internal communications—was accessed or exfiltrated. RLD, responsible for overseeing numerous professional and occupational licenses across New Mexico, did not release specifics about operational disruptions or potential service delays stemming from the incident. Authorities emphasized their confidence in the containment measures but refrained from detailing the technical methods used to isolate affected systems or prevent further unauthorized activity. No ransomware claims, extortion attempts, or public data leaks were immediately associated with the breach. The Cybersecurity Office continued its forensic examination to establish the intrusion’s origin, extent, and consequences while maintaining public assurances that mitigated risks no longer threatened ongoing operations.

Sources

Sources available to members: 1 source.

CSIDB