The Los Angeles City Attorney’s Office takes the protection of personal information seriously. As part of our commitment to protecting personal information, we are sharing an update on the results of our data review associated with a data security incident at the City Attorney’s Office earlier this year. This update describes the incident, the measures we have taken, and steps individuals may consider taking in response to this incident.
What Happened? On March 20, 2026, we became aware of suspicious activity involving data stored in a file-sharing platform the Office used to share discovery-related material in civil cases with other counsel and parties to litigation. We immediately launched an investigation, secured the file share, and determined that an unauthorized actor used a compromised credential to acquire data from the file share between December 28, 2025, and January 22, 2026. We then engaged an independent third party to complete a thorough review of the data to identify the specific personal information involved.
What Information Was Involved? On August 20, 2026, we completed our data review and determined the data contained personal information belonging to certain California residents maintained in connection with prior or ongoing litigation and shared through the file-sharing platform. The information involved varied by individual, based on what was collected and shared in the course of civil litigation, but may have included the following information: names, driver’s license or other government document identification numbers, medical information, and health insurance information. For a limited number of individuals, the information may have included a Social Security number, financial account number, or username and password.
What We Are Doing. We immediately took steps to secure the affected system and prevent further access, including rotating all user credentials.We have also taken steps to enhance our existing security measures to prevent something like this from happening in the future. We will directly notify individuals whose information was involved, and for whom we have a physical mailing address, by U.S. mail. We will also notify individuals for whom we have only an email address by email.
What You Can Do. It is always a good idea to review account statements and free credit reports for any unauthorized activity. All individuals may request a free copy of their credit report weekly from the three nationwide credit reporting companies by visiting annualcreditreport.com. You may also contact the three nationwide credit reporting companies directly:
- Equifax, PO Box 740241, Atlanta, GA 30374, www.equifax.com, 1-888-378-4329
- Experian, PO Box 2002, Allen, TX 75013, www.experian.com, 1-888-397-3742
- TransUnion, PO Box 2000, Chester, PA 19016, www.transunion.com, 1-833-799-5355
Finally, we have opened a dedicated call center to address questions about this incident, available toll free at (844) 301-0078, Monday through Friday, 9:00 a.m. to 5:00 p.m. Pacific, excluding some major U.S. holidays.