CSIDB logo
Incident

California Department of Finance

Incident posture

Attack window
Dec 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-13 00:00

Linked entities

Victim
California Department of Finance
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Dec 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The California Department of Finance was targeted in a cyberattack claimed by the LockBit ransomware gang, which alleged theft of 75GB of data. State officials confirmed a cybersecurity incident, prompting response from multiple agencies including the California Cybersecurity Integration Center, Department of Technology, Military Department, and Highway Patrol. While the intrusion was proactively detected and no state funds were compromised, the ransomware group's data theft claims remain under investigation. The department continued its operations preparing the Governor’s Budget despite the incident.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 12, 2022, the California Department of Finance experienced a cybersecurity incident involving unauthorized intrusion into its systems. State officials publicly disclosed the breach the same day, confirming the activation of a coordinated response led by the California Cybersecurity Integration Center (Cal-CSIC). The Governor’s Office of Emergency Services stated the intrusion had been proactively identified through collaboration with state and federal security partners, though initial announcements provided limited technical details about the attack vector or initial access methods. Multiple agencies joined the response effort, including the California Department of Technology, the state Military Department, and the California Highway Patrol. Officials emphasized that no state funds were compromised during the incident, allowing the Department of Finance to continue preparing the Governor’s Budget scheduled for release the following month.

The LockBit ransomware gang claimed responsibility for the attack on December 13, 2022, asserting they had exfiltrated 75GB of data from the Department of Finance. This claim emerged one day after state authorities had acknowledged the cybersecurity incident without attributing it to any specific threat actor. Cal-CSIC continued its active investigation into both the intrusion and LockBit’s data theft assertions, though state officials did not publicly confirm the validity of the ransomware group’s data exfiltration claims. The incident prompted heightened operational coordination among California’s cybersecurity response entities, though critical financial systems remained unaffected. Departmental operations persisted throughout the investigation, with no reported disruption to budget preparation timelines or public financial management functions. Response efforts focused on containment, forensic analysis, and assessing potential data exposure while maintaining continuity of government operations.

Sources

Sources available to members: 2 sources.

CSIDB