DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

LA Housing Authority Confirms Breach Claimed by Cactus Ransomware: What the Evidence Shows

HACLA confirmed an attack and later unauthorized access involving personal information. Cactus’s 891-GB claim and definitive responsibility remain unverified.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Housing Authority of the City of Los Angeles (HACLA) confirmed that its information-technology network was attacked after the Cactus ransomware group claimed responsibility in late October or early November 2024. Cactus alleged it stole about 891 GB of data. HACLA later confirmed that unauthorized access occurred and that personal information may have been accessed, but the public record does not independently verify the 891-GB figure or definitively attribute the intrusion to Cactus.

This distinction matters for residents, voucher holders, employees, contractors and anyone who received a HACLA notice: the incident is real, while several of the attacker’s specific allegations remain unproven.

What happened

Cactus listed HACLA on its leak site and claimed to have taken approximately 891 GB of files. The group alleged that the material included personally identifiable information, database backups, financial documents, employee and executive information, customer records, internal correspondence and confidential agency data. Cactus also reportedly posted samples or screenshots as purported proof.

Those details came from the ransomware group itself. A leak-site post can establish that a claim was made, but it does not by itself prove the amount of data taken, the identity of the victim, or the completeness of the samples. Contemporary reporting is available from BleepingComputer and SC Media.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline of the HACLA incident

Date What the record says
October 7, 2024 The California Attorney General’s breach database lists this as HACLA’s breach date. It is filing metadata, not proof that attackers first entered the network that day. California Attorney General entry.
October 2024 HACLA says it identified suspicious activity.
November 1, 2024 News reports described Cactus’s claim. HACLA confirmed that its IT network had been attacked and said it had engaged outside forensic specialists.
January 9, 2025 HACLA board materials acknowledged the Cactus claim, including the alleged 891 GB, and said systems and essential services remained operational. HACLA board memo.
January 2025 A third-party vendor began reviewing potentially affected data.
July 2025 HACLA says it determined that personal information was present during the unauthorized access and may have been accessed.
December 5, 2025 HACLA’s formal data-security notice was dated and submitted, documenting the later findings. HACLA notice filed with the California Attorney General.
March 5, 2026 The notice’s stated deadline for eligible people to enroll in 12 months of IDX monitoring and restoration services.

What HACLA confirmed in November 2024

HACLA told BleepingComputer that its IT network had been attacked, that it had hired external forensic IT specialists, and that an investigation was underway. The agency said its systems remained operational and that it was following expert advice while continuing to serve low-income and vulnerable Los Angeles residents.

That initial statement did not establish the attackers’ entry method, whether files had been encrypted, whether Cactus was conclusively responsible, whether 891 GB was accurate, how many people were affected, or exactly which records had been accessed or copied.

What later official notices established

HACLA’s formal notice provides the strongest public evidence about the incident’s data-security impact. It says unauthorized access to HACLA systems occurred after suspicious activity was found in October 2024. Following forensic work and a vendor review that began in January 2025, HACLA concluded in July 2025 that personal information was present during the unauthorized access and may have been accessed.

The notice says HACLA notified the FBI and other law-enforcement agencies. At the time of the notice, HACLA said it had no evidence that the information had been misused. That statement describes what the agency had found then; it is not a guarantee that misuse can never occur.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Information that may have been involved

The notice lists these potentially affected data elements:

  • Dates of birth
  • Social Security numbers
  • Email addresses
  • Telephone numbers
  • Street addresses
  • Financial-account numbers
  • Diagnosis, treatment or procedure information

“Potentially involved” means the information may have been accessible during the unauthorized access. It does not mean every person had every listed data element, that all of it was exfiltrated, or that all HACLA residents were affected.

Services offered to eligible people

HACLA offered affected individuals 12 months of IDX credit-monitoring and identity-restoration services at no cost. Use the enrollment instructions and deadline in your official notice. The vendor’s general site is IDX; do not assume an unsolicited message or phone call using the IDX name is genuine.

Was this definitely a Cactus ransomware attack?

Not on the public evidence currently available. Cactus claimed the intrusion and the 891-GB theft. HACLA confirmed the underlying cyberattack, later confirmed unauthorized access and possible exposure of personal information, and discussed the Cactus claim in its January 2025 board memo. However, the formal breach notice does not publicly attribute the incident to Cactus in the available text.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The accurate formulation is therefore: HACLA confirmed an attack and later a data breach after Cactus claimed responsibility. It is not established that Cactus stole exactly 891 GB, that every file described by the group came from HACLA, or that the group’s attribution was forensically confirmed.

Did the attack disrupt housing services?

HACLA said its systems remained operational. Its January 2025 board material said essential services for Los Angeles’s low-income and vulnerable residents were not disrupted. Operational continuity does not eliminate investigation costs, remediation work or risk to people whose information was stored in the systems.

What remains unknown

  • The initial access method and the attackers’ precise dwell time.
  • Whether any HACLA files were encrypted.
  • The exact number of affected individuals.
  • The exact quantity and identity of data exfiltrated.
  • Whether the full 891 GB claimed by Cactus existed and belonged to HACLA.
  • Whether Cactus’s responsibility has been confirmed through forensic attribution.
  • Whether any later misuse occurred beyond HACLA’s statement that it had no evidence of misuse when it issued the notice.

What people who received a HACLA notice should do

  1. Use the official IDX offer. Enroll before the deadline printed in your notice if you are eligible. Save confirmation details and read what the monitoring and restoration service covers.
  2. Check your credit reports. Review all accounts and inquiries for unfamiliar activity. You can obtain the reports available through the nationwide credit-reporting system at no charge.
  3. Consider a credit freeze or fraud alert. This is general consumer-protection guidance, separate from HACLA’s monitoring offer. A freeze can make it harder for someone to open new credit in your name; a fraud alert asks creditors to take additional verification steps.
  4. Watch financial accounts and benefits communications. Report unauthorized transactions to the institution involved and keep copies of correspondence.
  5. Expect impersonation attempts. Be cautious of messages claiming to be from HACLA, IDX, law enforcement or a housing-service provider. Do not disclose passwords or one-time codes through an unsolicited contact, and do not click unfamiliar links.
  6. Do not pay “recovery” services. Criminals may use a breach announcement to demand money to recover data or unlock housing benefits. Contact HACLA through a number or website you already trust, or use the contact details in your mailed notice.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How this differs from HACLA’s earlier LockBit incident

HACLA had a separate earlier breach, discovered on December 31, 2022. Its investigation found unauthorized access to certain servers from January 15 through December 31, 2022, and determined in February 2023 that affected systems contained personal information. That event was publicly associated with LockBit and is not the same incident as the 2024 Cactus claim. HACLA’s earlier notice is available at HACLA’s English website notice.

What the incident means for organizations

HACLA’s board memo describes security improvements including Microsoft Sentinel for security monitoring and a planned move from SentinelOne to Microsoft Defender for Endpoint. These are enterprise tools, not products most residents need to buy. Agencies and property managers handling sensitive resident information should instead treat the incident as a reminder to maintain tested backups, centralized logging, endpoint detection, rapid isolation procedures and an incident-response plan with qualified forensic support.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s product pages provide background on Microsoft Sentinel and Microsoft Defender for Endpoint. HACLA’s memo is the source for the agency’s implementation plans.

Bottom line

HACLA confirmed that its network was attacked and later confirmed unauthorized access in which personal information may have been accessed. Cactus’s responsibility and its claimed 891-GB theft remain attributed claims rather than independently proven facts in the available public record. People who received an official notice should use the offered IDX protection, monitor accounts and credit, and stay alert for follow-on phishing.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.