Policy & Regulation
Hackers leak sensitive files from Los Angeles City Attorney’s office
Hackers have allegedly leaked 7.7 terabytes of sensitive data from a digital storage system belonging to the Los Angeles City Attorney’s Office, not the LAPD itself.
Cybercriminals have allegedly stolen and leaked sensitive internal documents from the Los Angeles Police Department (LAPD). However, the LAPD asserted that the security incident did not affect its own networks or systems. Instead, the breach affected a digital storage system belonging to the Los Angeles City Attorney’s Office, which is the government agency whose digital storage system was breached. The incident reportedly exposed 7.7 terabytes of data and more than 337,000 files. The exposed materials include police officer personnel files, internal affairs investigations—which are official inquiries into police officer conduct—and discovery documents, which are legal evidence exchanged between parties in a lawsuit. The incident highlights the complex ecosystem of municipal data storage, where a breach at one government agency—the Los Angeles City Attorney’s Office—can expose highly sensitive records belonging to another, such as the LAPD.
The hacker group responsible for the breach is World Leaks. Emma Best, the founder of the nonprofit transparency group Distributed Denial of Secrets, which hosts the leaked data, attributed the breach to World Leaks. Best characterized World Leaks as an extortion gang. According to the cybersecurity firm Halcyon, which analyzed the hackers, World Leaks is an apparent rebrand of Hunters International. Hunters International is the previous name of the hacker group World Leaks, which started its activities in January 2025.
Under California state law, most police officer records are deemed private. The Los Angeles Times characterized the incident as a “stunning breach of police data” because such records are rarely disclosed or published. In response to the unauthorized access, the LA City Attorney’s Office clarified that the breach involved a third-party tool. Ivor Pine, the spokesperson for the LA City Attorney’s Office, confirmed that the breach was limited to this specific application. Pine stated: “The information was self contained in this application without any links or access to any department records or systems.”
Why it matters
The exposure of sensitive personnel files and internal affairs investigations represents a significant security failure for municipal law enforcement infrastructure, highlighting the risks of third-party digital storage tools. For public agencies, the incident underscores the vulnerability of legal and law enforcement data when managed outside of core internal networks.