Skip to main content
Back to overview
High

Housing Authority of the City of Los Angeles hit by Cactus ransomware attack

The Housing Authority of the City of Los Angeles (HACLA) confirmed a cyberattack by the Cactus ransomware gang, which claimed to have stolen 891 GB of sensitive data, including personally identifiable information,…

Key points

  • Cactus ransomware gang claimed responsibility.
  • 891 GB of sensitive data allegedly stolen.
  • Compromised data includes PII, financial documents, and database backups.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Potential operational disruption

Availability

Published
Nov 4, 2024
Updated
Jul 2, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Availability
Likely asset
Server or cloud data store

Mentioned entities

HaclaHousing Authority of the CityLos AngelesCactusThe Housing Authority of theCity of Los AngelesHACLACompromisedPII

Quick context

Questions about this signal

What happened in this signal?

The Housing Authority of the City of Los Angeles (HACLA) confirmed a cyberattack by the Cactus ransomware gang, which claimed to have stolen 891 GB of sensitive data, including personally identifiable information, financial documents, and database backups. The incident was disclosed on November 4, 2024, marking it as the second major breach for HACLA in recent years.

When was this signal reported?

Shadow Tier lists Nov 4, 2024 as the signal date.

Which organization is connected to this signal?

Hacla is the organization connected to this public signal.

Explore Hacla
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents