On October 1, 2024, the Housing Authority of the City of Los Angeles appeared on the leak site operated by the Cactus ransomware group. The listing states that internal files were exfiltrated during a ransomware attack on the public agency responsible for providing affordable housing to low-income residents across Los Angeles.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch hacla.org
Get alerted the next time hacla.org files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about hacla.org’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The Cactus leak site lists HACLA as a victim and provides a direct onion-link download labeled “PROOF” that contains samples of the allegedly stolen material. The disclosure does not quantify how many records were taken, name the specific systems compromised, or reveal the ransom amount demanded. It simply states that data was exfiltrated and that the agency now faces public exposure if payment is not made. HACLA is described on the page with its official address at 2600 Wilshire Blvd, Los Angeles, revenue figure of $1.9 billion, and contact phone number, information that matches the agency’s public record.
Why This Matters for You and Your Family
If you or anyone in your household has ever lived in HACLA-managed housing, applied for assistance, or been part of their tenant screening process, your personal information may be among the internal files now held by attackers. Low-income families who rely on public housing are already under financial pressure; having names, addresses, dates of birth, Social Security numbers, or income documentation suddenly available to criminals adds a layer of risk that can lead to identity theft, fraudulent loan applications, or targeted scams. Even if the exact volume of records is unknown, the nature of housing authority data means everyday families—not corporations—are the ones exposed.
Doxxing and Identity-Chain Risks
Internal files from a housing authority frequently contain linked details that attackers can chain together: an email address tied to a tenant application, a phone number connected to emergency contacts, and addresses that reveal exactly where you live. These fragments become the foundation for doxxing campaigns. Once criminals correlate your information with usernames from other breaches, they can hijack online accounts, including gaming profiles belonging to you or your children. A single leaked housing record can therefore cascade into full identity exposure across social media, email, and gaming platforms.