Los Angeles city skyline at dusk with buildings lit up
Photo via Unsplash

TL;DR: A ransomware group called WorldLeaks breached the Los Angeles City Attorney's file-sharing system on March 20, 2026, and made 337,000 LAPD files (totaling 7.7 terabytes) available for download. The leaked data includes officer personnel records from the TEAMS II disciplinary tracking system, internal affairs investigations, unredacted criminal complaints with witness names, medical records, and discovery documents from civil litigation. The file-sharing system was not password-protected. The City Attorney's office waited weeks to disclose the breach. The Police Protective League called the lack of transparency "an understatement."

The Cops Got Hacked Through Their Own Lawyer's Office

On March 20, 2026, WorldLeaks (a ransomware collective known for extorting organizations by threatening to dump confidential files) breached a file-sharing system maintained by the LA City Attorney's Office [1]. The system held discovery documents from LAPD civil litigation. Settled cases. Active cases. Years of material.

The City Attorney's office created the system after the George Floyd protests in 2020, when civil rights lawsuits against LAPD started piling up. It was supposed to streamline how attorneys shared case documents. Instead, it became a massive, centralized target. And it grew far beyond its original scope, eventually housing hundreds of LAPD-related lawsuits' worth of sensitive material [2].

The kicker? The system lacked proper access restrictions. According to the Los Angeles Times investigation that broke the story on April 8, the file-sharing tool was not password-protected despite being intended to require authorization [2]. Seven terabytes of police records sitting behind... nothing.

Everything. They Got Everything.

The 337,000 files, 7.7 terabytes total, include some of the most sensitive records a police department produces:

  • Officer personnel files from the TEAMS II system: the LAPD's internal tracking database for arrests, training records, complaints, lawsuits, use-of-force incidents, commendations, and workers' compensation claims
  • Internal affairs investigations: records of officers investigated for misconduct
  • Unredacted criminal complaints: names, addresses, and identifying details of crime victims and witnesses that are legally supposed to stay confidential
  • Medical records: health information from litigation that's protected under state and federal law
  • Discovery documents: depositions, evidence, and legal strategy from civil cases against the LAPD

Under California law, most police officer records are considered private. Unauthorized disclosure is a crime. WorldLeaks didn't just steal data: they exposed the internal machinery of one of the country's largest police departments.

Some of the files started surfacing on social media before the breach was publicly acknowledged. An account called @WhosTheCop on X, which focuses on police accountability, began sharing leaked materials [3]. The posts were later removed, but by then, the files were already spreading.

Three Weeks of Silence

WorldLeaks announced the breach on March 20. The Los Angeles Times published its investigation on April 8. That's 19 days where the City Attorney's office knew it had been hit, and apparently didn't tell the people whose data was stolen.

City Attorney spokesperson Ivor Pine said the team "took immediate steps to secure the tool" once the compromise was identified and confirmed "no other City applications or systems were involved" [2]. That's lawyer-speak for "the damage is contained." But 337,000 files on an unpassword-protected system isn't contained: it's catastrophic.

The Police Protective League (the LAPD officers' union) wasn't notified either. Their response was blunt:

"To say we are disappointed by the lack of urgency and forthrightness from the City Attorney's office is an understatement." [2]

City Attorney Hydee Feldstein Soto now faces re-election scrutiny over the breach. Her challenger, John McKinney, called the response "unacceptable," warning that exposed witness identities and officer family information could put lives at risk [2].

Real People, Real Danger

This isn't an abstract data breach. When witness names leak from unredacted criminal complaints, people can be found. Intimidated. Hurt. Witnesses cooperate with police under the explicit promise that their identities will be protected. That promise just got shattered for every case in that database.

For officers, the TEAMS II records are a complete professional dossier. Use-of-force incidents. Complaints. Internal affairs investigations. Workers' comp claims that reveal injuries and medical conditions. In a city where about 900 officers are already suing over a separate 2023 mugshot release incident, this breach is gasoline on a dumpster fire [2].

And for the defendants and plaintiffs in hundreds of civil rights cases (people who sued the LAPD over excessive force, wrongful arrest, or civil rights violations) their legal strategies, depositions, and personal details are now public. That's not just a privacy violation. It could compromise active litigation and pending settlements.

The Surveillance State Can't Secure Its Own Records

The LAPD operates one of the most extensive surveillance networks in the country. Real-time crime centers. Automated license plate readers. Predictive policing algorithms. Facial recognition partnerships. They collect data on millions of people.

But they can't protect their own. A file-sharing system with no password protection. Discovery documents from sensitive litigation accessible to anyone who found the URL. An entire department's internal affairs history, just... sitting there.

This is the fundamental problem with mass data collection, whether it's a police department hoarding disciplinary records or a tech company stockpiling user profiles. Every database is a target. Every centralized repository is a single point of failure. And the organizations collecting the most data are often the worst at protecting it.

The LAPD told Security Magazine: "We take this incident very seriously and are working with the LA City Attorney's Office to gain access to the impacted files to understand the full scope of the data breach" [3]. Translation: they still don't fully know what was stolen. A month later.

Who Is WorldLeaks?

WorldLeaks is a ransomware collective that specializes in extorting organizations by threatening to publish stolen files online. They've hit both private companies and government entities. Their playbook is straightforward: breach, exfiltrate, demand payment, publish if refused.

The group first announced the LAPD breach on March 20 on their Tor-based leak site. When the City Attorney's office apparently didn't pay up (or didn't respond fast enough) the files went public. This is the standard ransomware escalation playbook, and it worked exactly as designed against one of the largest cities in America.

The breach vector, an unprotected file-sharing system, suggests WorldLeaks didn't need particularly sophisticated techniques. When the front door is unlocked, you don't need a battering ram.

What This Means for You

If You're a Witness in an LAPD Case

Your identity may be compromised. Contact the DA's office or your attorney to ask if your case file was in the breached system. Consider safety planning if you testified against someone who might now learn your identity.

If You Filed a Lawsuit Against the LAPD

Your deposition, evidence, and legal strategy may be public. Contact your attorney immediately to assess whether this affects your case, especially if it's still active or pending settlement.

If You're an LAPD Officer

Your personnel records, disciplinary history, and possibly medical information are exposed. Contact the Police Protective League for guidance. Monitor for identity theft: your SSN and personal details may be in those files.

For Everyone Else

Remember this next time someone says we need more data collection for public safety. The organizations collecting the data can't even protect their own records. Every database is a future breach.

References

  1. Security Magazine - LAPD Records Hacked and Exposed (April 2026)
  2. The Spokesman-Review - How thousands of sensitive LAPD files got leaked online, and what happens next (April 10, 2026)
  3. Police1 - Sensitive LAPD materials, including officer personnel files, leaked in suspected hack (April 2026)
  4. TechRepublic - Massive Data Breach Exposes 337K LAPD-Linked Records (April 2026)
  5. FOX 11 Los Angeles - LAPD data breach: Thousands of confidential police records leaked in city attorney hack (April 2026)