The Office of the Los Angeles City Attorney discovered in March 2026 that an unauthorized actor used a stolen credential to access a file-sharing platform holding litigation discovery documents, exposing personal information between December 2025 and January 2026. Affected individuals received notice in August 2026. Anyone notified should activate the free Kroll identity monitoring service immediately and watch financial accounts for suspicious activity.
| Company | Office of the Los Angeles City Attorney |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Full Names, Personal Identifying Information from Litigation Files, Case-Specific Personal Data Elements |
| People Affected | Not Publicly Disclosed |
| Attack Method | Compromised Credential Access |
| Regulators Notified | California Attorney General, Vermont Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Office of the Los Angeles City Attorney Data Breach?
The Office of the Los Angeles City Attorney has disclosed a data breach involving a file-sharing platform the office used to exchange litigation discovery materials with outside counsel and other parties. The LA City Attorney data breach came to light in March 2026, when staff noticed unusual activity tied to the platform.
Once the office spotted the suspicious activity, it moved quickly to lock down the system. The investigation showed that someone outside the organization used a stolen login credential to get into the file share. That unauthorized actor pulled data from the platform sometime between December 28, 2025, and January 22, 2026.
After securing the file share, the office brought in outside experts to dig deeper into what actually happened. Because the platform held discovery files from multiple legal matters, investigators needed time to sort out exactly whose information sat inside the exposed documents. This kind of document-by-document review often takes months, since discovery files can contain scanned records, spreadsheets, and other materials layered with personal details.
The office finished that detailed review in August 2026. At that point, it identified the specific individuals whose personal information appeared in the compromised files and began preparing notification letters. As a result, the gap between the initial discovery in March and the notification in August reflects the time needed to confirm exactly what data was involved.
Who was affected?
The individuals affected by this incident appear to be people whose personal information showed up in litigation discovery files handled by the Los Angeles City Attorney’s office. Because the platform was used to share case-related materials with opposing counsel and other parties, the affected population likely includes people connected to civil lawsuits involving the city.
The notification letter does not state a specific number of individuals affected, so that figure has not been publicly disclosed. Similarly, the source material does not specify whether minors were among those impacted or whether the affected individuals were concentrated in a particular geographic area. Anyone who received a formal notice by mail should assume their information was part of the exposed files.
What Information Was Potentially Exposed?
The notification letter indicates that the exposed files contained personal information tied to specific individuals, though the exact categories differ from person to person depending on which discovery documents included their data. Because litigation files often combine several types of records, the range of exposed information can be broad.
- Full names
- Personal identifying information contained within litigation discovery documents
- Data elements specific to each individual’s involvement in the underlying legal matters
Given the nature of civil litigation discovery, this kind of material can sometimes include sensitive details such as financial records, medical information, or other personal data depending on the case. When this type of information ends up in the wrong hands, it can create a foundation for identity theft. For instance, a bad actor could use exposed personal details to open new credit accounts or file fraudulent tax returns.
In addition, exposed information from legal proceedings can be misused for targeted phishing attempts. Because attackers often know details about a person’s specific legal situation, they can craft convincing messages that impersonate attorneys, courts, or government offices. This makes it especially important for affected individuals to treat unexpected calls or emails with caution, even if they reference real case details.
What is the company doing?
In response to the incident, the office secured the affected file-sharing platform right away and launched a full investigation. It also brought in an independent third party to review the compromised data and pin down exactly whose information was involved.
The office has also filed formal notification with the California Attorney General and the Vermont Attorney General, consistent with state breach notification requirements. To help affected individuals guard against misuse of their data, the office arranged for Kroll to provide 12 months of complimentary identity monitoring. This service includes credit monitoring, fraud consultation, and identity theft restoration support.
Beyond notification and monitoring, the office says it has strengthened its existing security measures to reduce the risk of similar incidents happening again. This suggests changes to how the file-sharing platform is accessed and monitored going forward.
What Should Affected Individuals Do?
Enroll in the Complimentary Identity Monitoring
Anyone who received a notification letter should activate the free Kroll identity monitoring service as soon as possible. The letter includes a membership number and an activation deadline, so it’s important to act before that window closes.
This service tracks changes to your credit file and flags anything unusual, such as a new credit application you didn’t authorize. Because early detection often makes a major difference in limiting damage, enrolling promptly gives you a head start if fraud does occur.
Monitor Your Credit Reports and Account Statements
Beyond the offered monitoring service, affected individuals should regularly check their own bank and credit card statements for unfamiliar charges. You can also request a free weekly credit report from each of the three major credit bureaus through annualcreditreport.com.
Reviewing these reports helps you catch new accounts or inquiries you don’t recognize. If you spot anything suspicious, contact the relevant bureau or financial institution right away to dispute it before it escalates.
Consider a Fraud Alert or Credit Freeze
Because the exposed data may include information that could be used to open new accounts, placing a fraud alert or credit freeze with the three credit bureaus adds an extra layer of protection. A fraud alert requires lenders to verify your identity before extending new credit in your name.
A credit freeze goes a step further by blocking access to your credit file entirely until you lift it. As a result, it’s one of the strongest tools available for preventing someone from opening accounts using your stolen information.
Stay Alert to Phishing Attempts
Because this breach involved litigation-related documents, affected individuals should be especially cautious of messages referencing legal matters, court dates, or case details. Scammers sometimes use real information from a breach to make phishing attempts look more convincing.
Therefore, avoid clicking links or sharing personal details in response to unexpected emails, texts, or calls, even if they appear to reference an actual legal proceeding. Instead, verify any request by contacting the office directly through a phone number you look up independently.
Know Your Legal Options
If you believe your personal information was mishandled or misused following this breach, it may be worth speaking with a data breach attorney about your options. An attorney can help you understand whether you qualify for compensation and what steps to take next.
Many attorneys offer free case evaluations, so there’s little downside to asking questions. This is especially useful if you’ve already noticed signs of fraud or identity theft tied to this incident.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
Official data breach notification from California Attorney General
View the public data breach notification listing from Vermont Attorney General
