On April 13, 2024, the District of Columbia’s Department of Insurance, Securities, and Banking (DISB) appeared on the LockBit 3.0 ransomware leak site, claiming that internal files had been exfiltrated during a ransomware attack. The listing indicates that anyone whose personal or financial information is held by the agency could be affected, even though the exact number of impacted individuals remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch disb.dc.gov
Get alerted the next time disb.dc.gov files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about disb.dc.gov’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The LockBit 3.0 panel states that DISB’s internal files were exfiltrated after the agency failed to meet the group’s ransom deadline. The disclosure does not specify the volume or exact types of records taken, only that the data consists of “internal files.” No sample documents have been publicly released on the leak site as of the initial posting. The notification aligns with the agency’s mission statement describing its role in regulation, consumer protection, financial education, and small-business financing for District residents and businesses.
Why This Matters for You and Your Family
When a government agency responsible for insurance, banking, and securities records is breached, the exposure often includes names, addresses, dates of birth, Social Security numbers, policy details, licensing information, or complaint records. Even without a precise count, the breach represents a concrete risk for any DC resident or business that has interacted with DISB. Your family’s financial and identity data held by the agency could now sit in an attacker’s archive, ready for sale or further extortion. The incident underscores how local government offices that handle everyday personal paperwork have become routine targets.
Doxxing and Identity-Chain Risks
Exfiltrated internal files frequently contain enough overlapping details to link an individual’s government records to their email addresses, phone numbers, and online handles. Once attackers or data brokers possess these connections, they can build persistent identity profiles that follow you across services. Credential leaks tied to government systems often cascade into account takeovers on banking, insurance, tax, and email platforms. Children’s records held in family policy or licensing files can also surface, exposing minors to long-term identity theft and gaming-account compromises that begin with a parent’s leaked address or phone number.