Data breached at LA Housing Authority after ransomware attack

Ransomware
(Image credit: Pixabay)

The Housing Authority of the City of Los Angeles (HACLA) suffered a ransomware attack and had its data leaked to the dark web, the media reported earlier this week.

According to a BleepingComputer report, the state-chartered organization, which provides affordable housing to low-income families in LA, recently published a breach notice detailing a ransomware attack that occurred on December 31, 2022.

When the company’s IT team spotted the intrusion, they were forced to bring the servers offline and investigate the matter further.

Lurking for a year

The investigation, which was completed a month and a half later (on February 13, 2023), had shown that the threat actors might have had access to the target network and its endpoints for a full year (January 15, 2022 - December 31, 2022). 

After a full year of dwell time, the hackers made away with a wide array of sensitive customer data. 

This includes full names, social Security Numbers, dates of birth, passport numbers, driver’s license numbers, state ID numbers, tax ID numbers, military ID numbers, government-issued ID numbers, credit/debit card numbers, financial account numbers, health insurance information, and medical information.

The organization also said it notified affected customers by email, instructed them on how to monitor their accounts, place fraud alerts, and report potential identity theft. 

On the day the breach was spotted, the infamous LockBit 3.0 ransomware gang published samples of the stolen data on its leak website, claiming responsibility for the attack. It also threatened to release the entire batch, unless its (undefined) ransom demands are met. 

BleepingComputer later reported that the group leaked the entire database on January 27, but the link became inactive a month and a half later. The publication also said that there is no evidence that any other threat actors obtained this data, either.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Data leak
Ransomware attackers leak stolen Rhode Island private info following hack
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
Security
American National Insurance Company breach data found online
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
WordPress on a laptop
Over 20,000 WordPress sites hit by damaging malware campaign
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Latest in News
Boston Dynamics all electric Altas
This robot can do a cartwheel better than me and now I'm freaking out – but in a good way
A image of Saros character Arjun
Housemarque’s boss is surprisingly positive about Sony’s acquisition – and it’s good news for Saros
Oura Ring 4
One of Apple's top health execs is ditching the company for Oura, and I've never been more convinced smart rings are the future
Nvidia logo
Nvidia RTX 5060 Ti could be delayed to mid-April and RTX 5060 to mid-May – is AMD starting to look like a clear winner in the battle of Blackwell vs RDNA 4 GPUs?
The A Minecraft Movie Meal from McDonald's.
McDonald's reveals A Minecraft Movie meal with a bizarre set of collectibles and the most sinister sounding sauce ever
Apple iPhone 16e REVIEW
The iPhone 16e’s 5G performance seemingly has the iPhone 16’s beat