On January 11, 2026, the City of Seal Beach and its Police Department appeared on the leak site operated by the qilin ransomware group. The attackers claim to have stolen internal files during a ransomware incident and have published a sample of the allegedly exfiltrated data as proof.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
What Public Reporting Shows
Public reporting indicates the municipalities were listed on the qilin leak site with a claim that internal data had been exfiltrated. The exact volume of records and the specific types of information taken have not been independently verified by third parties. No confirmed count of affected residents or employees has been released. The listing follows the group’s typical pattern of posting proof-of-compromise samples after an organization declines to pay the demanded ransom.
Why This Matters for You and Your Family
When a local government and its police department suffer a breach, the information at risk often includes details that touch everyday residents. Internal files can contain names, addresses, dates of birth, driver’s license numbers, police reports, permit applications, and employee records. Any of these can be used to open accounts in your name, file fraudulent tax returns, or impersonate you with government agencies. If your family has interacted with Seal Beach city services—paying a parking ticket, filing a report, or applying for a business license—your information may be among the records now in criminal hands. The breach also raises concerns about sensitive police data that could expose victims, witnesses, or officers.
The Doxxing and Identity-Chain Risk
Ransomware groups rarely stop at posting generic files. Once internal documents surface, opportunistic criminals scrape them for email addresses, usernames, and phone numbers. These pieces are then fed into automated tools that link your online handles to your real identity, creating what security analysts call an identity chain. A single leaked city record can cascade into doxxing attempts, targeted phishing, or even swatting. Gaming accounts belonging to you or your children are especially vulnerable because kids often reuse the same email or password across school logins, city recreation portals, and popular games. A credential exposed in this claimed breach can quickly lead to account takeovers that reveal home addresses, family photos, and real-time location data.