The Housing Authority of the City of Los Angeles (HACLA) confirmed that its information-technology network was attacked after the Cactus ransomware group claimed responsibility in late October or early November 2024. Cactus alleged it stole about 891 GB of data. HACLA later confirmed that unauthorized access occurred and that personal information may have been accessed, but the public record does not independently verify the 891-GB figure or definitively attribute the intrusion to Cactus.
This distinction matters for residents, voucher holders, employees, contractors and anyone who received a HACLA notice: the incident is real, while several of the attacker’s specific allegations remain unproven.
What happened
Cactus listed HACLA on its leak site and claimed to have taken approximately 891 GB of files. The group alleged that the material included personally identifiable information, database backups, financial documents, employee and executive information, customer records, internal correspondence and confidential agency data. Cactus also reportedly posted samples or screenshots as purported proof.
Those details came from the ransomware group itself. A leak-site post can establish that a claim was made, but it does not by itself prove the amount of data taken, the identity of the victim, or the completeness of the samples. Contemporary reporting is available from BleepingComputer and SC Media.
#1 Best Overall
Timeline of the HACLA incident
| Date | What the record says |
|---|---|
| October 7, 2024 | The California Attorney General’s breach database lists this as HACLA’s breach date. It is filing metadata, not proof that attackers first entered the network that day. California Attorney General entry. |
| October 2024 | HACLA says it identified suspicious activity. |
| November 1, 2024 | News reports described Cactus’s claim. HACLA confirmed that its IT network had been attacked and said it had engaged outside forensic specialists. |
| January 9, 2025 | HACLA board materials acknowledged the Cactus claim, including the alleged 891 GB, and said systems and essential services remained operational. HACLA board memo. |
| January 2025 | A third-party vendor began reviewing potentially affected data. |
| July 2025 | HACLA says it determined that personal information was present during the unauthorized access and may have been accessed. |
| December 5, 2025 | HACLA’s formal data-security notice was dated and submitted, documenting the later findings. HACLA notice filed with the California Attorney General. |
| March 5, 2026 | The notice’s stated deadline for eligible people to enroll in 12 months of IDX monitoring and restoration services. |
What HACLA confirmed in November 2024
HACLA told BleepingComputer that its IT network had been attacked, that it had hired external forensic IT specialists, and that an investigation was underway. The agency said its systems remained operational and that it was following expert advice while continuing to serve low-income and vulnerable Los Angeles residents.
That initial statement did not establish the attackers’ entry method, whether files had been encrypted, whether Cactus was conclusively responsible, whether 891 GB was accurate, how many people were affected, or exactly which records had been accessed or copied.
What later official notices established
HACLA’s formal notice provides the strongest public evidence about the incident’s data-security impact. It says unauthorized access to HACLA systems occurred after suspicious activity was found in October 2024. Following forensic work and a vendor review that began in January 2025, HACLA concluded in July 2025 that personal information was present during the unauthorized access and may have been accessed.
The notice says HACLA notified the FBI and other law-enforcement agencies. At the time of the notice, HACLA said it had no evidence that the information had been misused. That statement describes what the agency had found then; it is not a guarantee that misuse can never occur.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Information that may have been involved
The notice lists these potentially affected data elements:
- Dates of birth
- Social Security numbers
- Email addresses
- Telephone numbers
- Street addresses
- Financial-account numbers
- Diagnosis, treatment or procedure information
“Potentially involved” means the information may have been accessible during the unauthorized access. It does not mean every person had every listed data element, that all of it was exfiltrated, or that all HACLA residents were affected.
Rank #3
Services offered to eligible people
HACLA offered affected individuals 12 months of IDX credit-monitoring and identity-restoration services at no cost. Use the enrollment instructions and deadline in your official notice. The vendor’s general site is IDX; do not assume an unsolicited message or phone call using the IDX name is genuine.
Was this definitely a Cactus ransomware attack?
Not on the public evidence currently available. Cactus claimed the intrusion and the 891-GB theft. HACLA confirmed the underlying cyberattack, later confirmed unauthorized access and possible exposure of personal information, and discussed the Cactus claim in its January 2025 board memo. However, the formal breach notice does not publicly attribute the incident to Cactus in the available text.
Free tools Windows power users keep installed
One-click scans. No signup required.
The accurate formulation is therefore: HACLA confirmed an attack and later a data breach after Cactus claimed responsibility. It is not established that Cactus stole exactly 891 GB, that every file described by the group came from HACLA, or that the group’s attribution was forensically confirmed.
Rank #4
Did the attack disrupt housing services?
HACLA said its systems remained operational. Its January 2025 board material said essential services for Los Angeles’s low-income and vulnerable residents were not disrupted. Operational continuity does not eliminate investigation costs, remediation work or risk to people whose information was stored in the systems.
What remains unknown
- The initial access method and the attackers’ precise dwell time.
- Whether any HACLA files were encrypted.
- The exact number of affected individuals.
- The exact quantity and identity of data exfiltrated.
- Whether the full 891 GB claimed by Cactus existed and belonged to HACLA.
- Whether Cactus’s responsibility has been confirmed through forensic attribution.
- Whether any later misuse occurred beyond HACLA’s statement that it had no evidence of misuse when it issued the notice.
What people who received a HACLA notice should do
- Use the official IDX offer. Enroll before the deadline printed in your notice if you are eligible. Save confirmation details and read what the monitoring and restoration service covers.
- Check your credit reports. Review all accounts and inquiries for unfamiliar activity. You can obtain the reports available through the nationwide credit-reporting system at no charge.
- Consider a credit freeze or fraud alert. This is general consumer-protection guidance, separate from HACLA’s monitoring offer. A freeze can make it harder for someone to open new credit in your name; a fraud alert asks creditors to take additional verification steps.
- Watch financial accounts and benefits communications. Report unauthorized transactions to the institution involved and keep copies of correspondence.
- Expect impersonation attempts. Be cautious of messages claiming to be from HACLA, IDX, law enforcement or a housing-service provider. Do not disclose passwords or one-time codes through an unsolicited contact, and do not click unfamiliar links.
- Do not pay “recovery” services. Criminals may use a breach announcement to demand money to recover data or unlock housing benefits. Contact HACLA through a number or website you already trust, or use the contact details in your mailed notice.
How this differs from HACLA’s earlier LockBit incident
HACLA had a separate earlier breach, discovered on December 31, 2022. Its investigation found unauthorized access to certain servers from January 15 through December 31, 2022, and determined in February 2023 that affected systems contained personal information. That event was publicly associated with LockBit and is not the same incident as the 2024 Cactus claim. HACLA’s earlier notice is available at HACLA’s English website notice.
What the incident means for organizations
HACLA’s board memo describes security improvements including Microsoft Sentinel for security monitoring and a planned move from SentinelOne to Microsoft Defender for Endpoint. These are enterprise tools, not products most residents need to buy. Agencies and property managers handling sensitive resident information should instead treat the incident as a reminder to maintain tested backups, centralized logging, endpoint detection, rapid isolation procedures and an incident-response plan with qualified forensic support.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
Microsoft’s product pages provide background on Microsoft Sentinel and Microsoft Defender for Endpoint. HACLA’s memo is the source for the agency’s implementation plans.
Bottom line
HACLA confirmed that its network was attacked and later confirmed unauthorized access in which personal information may have been accessed. Cactus’s responsibility and its claimed 891-GB theft remain attributed claims rather than independently proven facts in the available public record. People who received an official notice should use the offered IDX protection, monitor accounts and credit, and stay alert for follow-on phishing.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




