Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Deq Cyberattack topic
No spam. Unsubscribe anytime.
DEQ asks $1.12 million after April cyber attack; agency says notifications complete
Summary
The Oregon Department of Environmental Quality requested $1,121,515 in one‑time general fund to cover legal, contractor and communications costs tied to an April 2025 cyber attack; DEQ said forensic work is complete, impacted individuals were notified under OCIPA and systems have been secured.
Get email alerts on the Deq Cyberattack topic
No spam. Unsubscribe anytime.
The Oregon Department of Environmental Quality asked the Joint Interim Committee on Ways and Means subcommittee on Jan. 13 for $1,121,515 in one‑time general fund to cover remaining costs from an April 2025 cyber attack that forced the agency to shut down its network.
Director Leah Feldon told the committee that while the state's enterprise security lead, DAS Enterprise Information Services, determined the cause and declined to disclose exploit details for security reasons, DEQ’s role focused on privacy: identifying what records were accessed, who was impacted and ensuring legal notifications were made. Matt Davis, policy and external affairs administrator, said DEQ has completed analyses of compromised records, provided direct notifications to every impacted individual and offered privacy protection services where required under the Oregon Consumer Information Protection Act (OCIPA).
Davis outlined the agency’s remaining expenses: roughly $32,500 in Department of Justice assessments, about $75,650 in personal services for a project manager loaned from ODOT for communications and just over $1,000,000 for IDX, the cybersecurity contractor procured by EIS for forensic analysis and notification support. He told legislators that DEQ has absorbed nearly $900,000 in equipment replacement costs and seeks reimbursement only for items it cannot absorb without harming central services.
Committee members pressed DEQ on why notifications took months to complete; Feldon said the vendor‑driven forensic review required careful, manual verification of thousands of documents to avoid over‑notification and to ensure accuracy. She described a phased notification: initial groups in July and August, later groups in early and late December, and a final completion date of Dec. 30. Feldon said the agency prioritized accuracy to avoid unnecessary alarm and provided trauma‑informed supports, translated materials and a staffed call center for recipients.
DAS Chief Financial Office staff and the Legislative Fiscal Office recommended the appropriation; the subcommittee moved the LFO recommendation and voted to approve it.
DEQ said public‑facing systems such as vehicle inspection, DEQ Online interfaces with DMV, Oregon Buys and Workday payroll were verified as secure early in the incident, and that the breach affected older servers containing personal information from legacy records. The agency has updated data collection, storage and retention policies as part of its remediation.
The committee approved the LFO recommendation; the request will be considered as part of a 2026 budget reconciliation bill. The agency said it will continue working with EIS and DOJ as needed and will provide follow‑up information as investigations permit.
