10 Avril

WorldLeaks ransomware group dumps 7.7TB of confidential LAPD records

The Los Angeles Police Department is dealing with a catastrophic data breach after hackers stole and published nearly 340,000 sensitive files from the city attorney’s office. The ransomware collective WorldLeaks claimed responsibility for the attack, which exposed 7.7 terabytes of data including officer personnel files, disciplinary records, witness names, and medical information.

The breach originated from a file-sharing system the city attorney’s office created after the George Floyd protests. The system was designed to let attorneys access discovery materials from lawsuits involving police misconduct. According to sources familiar with the investigation, this system had no password protection. City officials believed it needed to remain accessible to outside attorneys and opposing counsel.

What started as a limited tool for protest-related cases expanded over time. It eventually stored records from hundreds of lawsuits involving the LAPD. The hackers exploited vulnerabilities in this third-party tool to extract the massive trove of data.

WorldLeaks first announced the breach on March 20. The group has built a reputation for extorting public and private entities by threatening to dump confidential files online. They were also reportedly behind a hack of L.A. Metro last month that forced the transit system to shut down parts of its network.

The leaked files include some of the most closely guarded secrets in California law enforcement. California has some of the nation’s strictest confidentiality laws protecting police personnel records. The files now circulating online include unredacted criminal complaints, internal affairs investigations, and detailed witness statements.

The LAPD only learned the full extent of the leak after the Los Angeles Times published a story revealing files had appeared online. The department issued a statement clarifying that the breach did not involve LAPD systems directly - the compromise was limited to the city attorney’s file-sharing tool.

The city attorney’s office says it took immediate steps to secure the tool once it discovered the compromise. They are working with law enforcement and forensic specialists to investigate. The office has not disclosed whether hackers demanded a ransom or whether the city paid one.

The political fallout could be significant. The breach puts Mayor Karen Bass and Police Chief Jim McDonnell in a difficult position. They must now manage the exposure of sensitive officer information while maintaining public trust. The leaked disciplinary files could reveal patterns of misconduct that were previously hidden from public view.

For the officers whose files are now public, the consequences are immediate and personal. Medical records, psychological evaluations, and details about their families are circulating on the internet. Witnesses named in the files may face intimidation or worse.

The technical failures here are stunning. A system containing some of the most sensitive law enforcement data in the nation operated without basic password protection. The expansion of the system beyond its original scope went unchecked. No one appears to have conducted a serious security review as the volume of sensitive data grew.

This is not a sophisticated supply chain attack or a novel zero-day exploit. The hackers found an open door and walked through it. The city built a system to share sensitive litigation documents and forgot to add a lock.

The incident raises serious questions about how other cities handle discovery materials in police misconduct cases. If Los Angeles made this mistake, others likely have too.

Mots-cles

lapd data breach ransomware worldleaks police records cybersecurity