Sensitive internal documents linked to the Los Angeles Police Department (LAPD) have reportedly been stolen and leaked online following a cyberattack, according to multiple reports and cybersecurity sources.
The breach is said to involve a large volume of confidential material, including police personnel files, internal affairs investigations and legal discovery documents. According to the Los Angeles Times, some of the files may contain unredacted complaints and highly sensitive personal data such as witness identities and medical information.
Details surrounding the incident remain partially unclear, and officials have not independently verified the full extent or authenticity of the leaked data. The LAPD has acknowledged that an investigation is underway, but stressed that its own internal systems were not directly compromised.
Instead, authorities say the breach appears to be linked to a separate digital storage system used by the Los Angeles City Attorney’s Office. In a public statement, the department said it is working with city officials to access the affected files and assess the scope of the exposure.
A spokesperson for the City Attorney’s Office confirmed that there had been “unauthorized access to a third-party tool,” though no further details were provided about the platform involved. Officials added that the compromised data was contained within that application and did not directly connect to other municipal systems.
Cybersecurity observers say the breach could still carry significant implications. Even if core police networks were not infiltrated, the exposure of legal and investigative documents could pose risks to ongoing cases, informants and individuals referenced in the files.
Emma Best, founder of the transparency group Distributed Denial of Secrets, said in an online post that the ransomware-linked group known as World Leaks was behind the incident. According to Best, some of the data was briefly published on the group’s leak site before being removed, a tactic often used to pressure victims into paying ransom demands.
It remains unclear why the data is no longer publicly listed. Such removals can happen for several reasons, including negotiations, internal disputes within hacker groups or attempts to avoid heightened scrutiny from law enforcement.
The reported scale of the breach is substantial. Estimates suggest that around 7.7 terabytes of data and more than 337,000 files may have been exposed. If confirmed, this would represent one of the most significant known leaks involving US law enforcement records in recent years.
Under California law, many police personnel records are considered private and are rarely made public. As a result, the potential exposure of such material has been described by observers as highly unusual and potentially damaging.
The case also highlights a broader vulnerability increasingly exploited by cybercriminals. Rather than targeting heavily secured government systems directly, attackers are often focusing on third-party vendors and external tools, which may offer easier entry points into sensitive data environments.
World Leaks, the group reportedly linked to the breach, emerged in early 2025 and is believed to be a rebranded version of a previous cybercrime operation known as Hunters International. Since then, it has been associated with attacks across multiple sectors, including healthcare, manufacturing and technology.
According to cybersecurity firm Halcyon, the group has demonstrated the ability to breach high-profile organizations, including defense contractors and major corporations. However, attribution in cyber incidents can be difficult to confirm, and officials have not publicly verified the group’s involvement in this case.
The incident comes amid growing concerns over the security of public institutions and the increasing sophistication of cyberattacks. Experts warn that even indirect breaches, such as those involving contractors or partner systems, can have serious real-world consequences.
For now, authorities say their priority is to determine exactly what data was accessed and whether it has been further distributed. Officials have not yet said whether affected individuals will be notified, or what steps may be taken to mitigate potential harm.
As investigations continue, the breach underscores a persistent challenge facing governments worldwide: securing vast amounts of sensitive data in an increasingly complex digital ecosystem where the weakest link is often outside their direct control.

