Another ransomware operation, the LockBit gang, now threatens to leak the files that have been stolen from the city of Oakland's systems.

Despite their efforts, the LockBit gang has not yet presented any evidence that it has stolen files from the Oakland city network.
The recent entry on the LockBit data leak website dark web is a warning that all their information will be disclosed in just 19 days, on April 10.
LockBit was not honest in at least one instance, consequently undermining its credibility.
See also: New Exfiltrator-22 kit linked to LockBit ransomware
Τον Ιούνιο του 2022, η ομάδα ransomware έκανε μια δήλωση ότι είχε διεισδύσει στα συστήματα της Mandiant και είχε πάρει εκατοντάδες χιλιάδες αρχεία. Παραδόξως, όμως, ο ισχυρισμός κατέληξε να είναι ένα τέχνασμα για να τραβήξει την προσοχή, αφού δημοσίευσαν μια δήλωση με την οποία αρνούνταν οποιαδήποτε σύνδεση με τη συμμορία ηλεκτρονικού εγκλήματος Evil Corp, αντί να αποκαλύψουν οποιεσδήποτε κλεμμένες πληροφορίες.
The city of Oakland has not yet given any answer regarding the claims made by the LockBit ransomware gang.
Just two months after the initial cyberattack in February, another ransomware gang took responsibility for the data theft from the city of Oakland. This follows the admission of Play ransomware's involvement earlier in March.
The Play gang then began revealing the allegedly stolen City of Oakland data, which consisted of 10GB multi-part RAR files containing highly sensitive documents, employee information, passports , and IDs.
See also: HACLA informs that after the Lockbit ransomware attack, data was leaked
The personal data of employees leaked online
After taking responsibility for the attack by the Play ransomware gang, the City quickly issued a statement and began thorough investigations into what was leaked on March 15. Those affected by this breach were immediately sent notification letters to ensure transparency.
The City also informed its employees that some of their sensitive personal information had been obtained from compromised systems , including names and addresses, driver's license numbers , and social security numbers.
On February 8, the city of Oakland had no choice but to shut down its IT systems when a ransomware, prompting it to declare a local state of emergency that same day. As they worked to secure their network, all of their technology infrastructure remained down until then.
While the city's 911 and emergency services were thankfully unscathed, other systems had to be taken offline due to this ransomware attack. This included phone service and any system used to file reports, collect payments, issue permits or licenses.

The city's systems are likely to be online next month
The official website of the Municipality has a page dedicated to providing the latest information and progress on the restoration of services affected by the February ransomware attack. However, this page has not been updated since March 8 – almost two weeks ago.
On Monday, Oakland Mayor Sheng Thao announced at a press conference that the city is still trying to restore all systems that were compromised and has requested the FBI's assistance in investigating the incident.
Mayor Sheng Thao expressed hope that the city will be back in operation within a few weeks to a month.
Information source: bleepingcomputer.com
