CSIDB logo
Incident

Los Angeles City Attorney

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-16 03:15

Linked entities

Victim
Los Angeles City Attorney
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Mar 2026
Discovered
Apr 2026
Disclosed
Mar 2026
Resolved
Pending

Summary

The breach involved the Los Angeles city attorney’s office file‑sharing system, which was accessed without authorization and used to copy hundreds of thousands of files related to LAPD civil litigation, including personnel records, medical reports, autopsy photos, witness names and body‑camera footage. The exposed data came from settled cases such as trip‑and‑fall incidents, excessive‑force allegations and sexual‑assault claims, and was later posted on a dark‑web site by a ransomware group that claimed responsibility. City officials said the incident was confined to the third‑party tool and notified the FBI, while police unions and elected leaders criticized the delayed disclosure and demanded a full explanation of how the unprotected system was allowed to operate.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The breach began when hackers exploited vulnerabilities in a file‑sharing system used by the Los Angeles city attorney’s office to transfer discovery materials to opposing counsel and litigants, a system that was not password‑protected because officials believed it needed to be accessible to outside attorneys. Sources familiar with the investigation said the system, initially created to handle the surge of lawsuits after the George Floyd protests, expanded to include records from hundreds of LAPD‑related lawsuits and was exploited by the ransomware collective WorldLeaks, which announced the breach on March 20. According to a partial inventory reviewed by The Times, nearly 340,000 files amounting to 7.7 terabytes were taken, including civil lawsuit documents, medical reports, autopsy photos, witness names, thousands of hours of uncut body‑camera footage, and personnel files from dozens of current and former officers stored in the TEAMS II system. The hackers teased small samples of the data on a dark‑web site starting March 20, published the full set on March 27, removed it after about eight hours, and then reposted it twice in early April. The city attorney’s office reported that an internal link used to access the files was clicked at least 5,000 times on the first day of the breach, which is thought to have occurred sometime in March, and confirmed that the files were not secured by a password.

Upon discovering the compromise, the city attorney’s office said it alerted senior LAPD officials and the city’s IT department, took immediate steps to secure the tool, and began regular contact with other city departments to assess the scope of the leak. A spokesperson for the office, Ivor Pine, stated that no other city applications or systems were involved and that the information remained self‑contained within the compromised application. The LAPD issued a public statement acknowledging the disclosure of discovery documents from previously adjudicated or settled civil litigation cases and emphasized that the breach did not involve any LAPD systems or networks. The FBI opened an investigation into the incident, and the city attorney’s office referenced an April 17 public report that described the incident as contained to a third‑party environment with no other city systems accessed or affected.

The leak generated political and operational repercussions. Councilmember Ysabel Jurado questioned when the city attorney’s office became aware of the breach, what actions were taken, and why officials were not notified promptly, noting that she had received only a high‑level internal report that left many details unaddressed. The Los Angeles Police Protective League, which had endorsed City Atty. Hydee Feldstein Soto for reelection, said it was disappointed by the lack of urgency and forthrightness from her office after learning of the hack on Tuesday evening. Feldstein Soto’s challenger, John McKinney, argued that the lack of transparency was unacceptable and could put witnesses and LAPD families at risk. Lawyers representing police officers reported numerous calls from clients concerned about exposed personnel and medical records, warning that the leaked material could be used to reopen old cases or initiate new litigation, including a case involving an alleged sexual assault by a police officer set for trial the following week. Experts cited in the coverage noted that government‑targeted hacks have risen sharply, with 165 recorded incidents targeting government agencies in the past year, and observed that AI‑powered tools have lowered the barrier for such attacks. The extent of downstream harm remains uncertain as an untold number of internet users have downloaded the data since its release.

Sources

Sources available to members: 2 sources.

CSIDB