Uptown neighbourhood in Oakland, California.
© eddie-hernandez.com/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

Oakland city officials confirmed on Wednesday that the hackers behind the February ransomware attack against the city have released 600 GB of personal data on the dark web.

The information likely belongs to current and former Oakland government employees, as the hackers had previously dumped 10 GB worth of personal data belonging to employees and some residents in February.

The City of Oakland announced it was hit by a ransomware attack on February 8, 2023. The next week the Interim City Administrator declared a local state of emergency to deal with the consequent network outages. During a press event on Wednesday, Mayor Sheng Thao said the city was working with law enforcement to address the issue. Thao also said that the city’s systems are 85% back online.

“We are still going through what has actually been taken and dropped onto the black web. As you know, it takes time to download and so we’re waiting for the full downloading of all this information,” Thao said.

“We are actively reaching out to anyone whose info may have been compromised, whether or not they work for the City of Oakland,” the mayor added.

Several city employees have voiced their frustrations with the lack of transparency surrounding the attack. The Oakland police officers’ union filed a claim for damages against the city last week. The union is also seeking credit monitoring services, bank monitoring services, credit restoration services and identity theft insurance.

Social Security Numbers, Home Addresses, and Medical Data Leaked

The latest dark web leak reportedly contains sensitive information such as social security numbers, home addresses, and medical data belonging to employees. It also has confidential information about residents who previously filed claims or applied for grants to the city.

“I’m equally upset, and obviously what is put out to the dark web cannot be taken back. I’m frustrated — my information is out there as well too — and so what we’re going to do is, we have to be proactive,” the mayor said.

Curiously, both the Play ransomware group and the LockBit ransomware gang have leaked data from the breach. The City of Oakland has yet to confirm if there is a sole perpetrator.

LockBit had previously falsely claimed responsibility for some cyberattacks. However, the group has had a recent track record of attacks against California government departments. In December 2022, the group breached and stole 76 GB of data from the California Department of Finance. In January 2023, it breached the Housing Authority of the City of Los Angeles, stealing 15 TB of data.

Other California-based authorities, such as the Los Angeles Unified School District (LAUSD), also suffered a debilitating ransomware attack in 2022.

Oakland to Invest in Upgrading IT Systems

Lawyers representing the Oakland police union claimed they repeatedly warned the city about vulnerabilities in its IT systems. Thao said on Wednesday that the city is looking to invest more resources into its IT systems to prevent future ransomware incidents. City Council President Nikki Fortunato Bas is also on board with this plan.

“It’s been a high priority, certainly as we go into our budget, I personally will make sure we’re investing,” said Fortunato Bas.

“In our ’21 cycle, I added over $3 million to our budget, for a chief security officer and to really make sure our systems are as up to date as possible and we’re going to keep doing that.”

The rise of ransomware may not come as a surprise to many, as even lesser-skilled cyber bandits can use ransomware-as-a-service. We also recommend reading up on identity theft which, unfortunately, is a common consequence of data leaks.

Curious to learn more about ransomware? VPNOverview recently spoke with five cybersecurity experts on the current state of ransomware.

Leave a comment