In March 2026, a group calling itself WorldLeaks published 7.7 terabytes of data stolen from the Los Angeles City Attorney’s office, including LAPD personnel files and internal affairs records, according to TechCrunch. The breach did not start with a weakness in the city’s own network. It started with a third-party tool used to share case files with outside attorneys, the same kind of vendor risk that shapes California cyber security for businesses far smaller than a city government.
What the breach means for California cyber security
The LA City Attorney data breach followed a familiar pattern. According to TechCrunch, the office confirmed unauthorized access to a third-party tool used to manage case files, not to any of the department’s core systems. A spokesperson for the office said the exposed information was self-contained within that one application, with no links to broader department records. That distinction matters. The office believed its main systems were protected. The vulnerability sat somewhere it was not watching as closely: a vendor platform handling sensitive files on its behalf.
The leaked data included officer personnel records and internal affairs investigations, all managed through one external tool. WorldLeaks, the group behind the leak, is a rebrand of a ransomware operation called Hunters International, according to TechCrunch. For California businesses, the lesson isn’t really about city government. It’s about how much sensitive data now sits with vendors, not in-house.
How third-party tools become entry points for attackers
Attackers don’t need to break through a business’s own defenses if there’s an easier way in through a vendor. Vendors and other software platforms often hold copies of sensitive data or a direct line into a business’s systems, without being held to the same security standard as the business itself. The Cybersecurity and Infrastructure Security Agency (CISA) has flagged this as a persistent problem for small and mid-sized organizations, noting that a business’s exposure depends on the practices of every vendor it works with, not only its own defenses.
This shows up constantly in ordinary business operations. A payroll system or a file-sharing tool can hold data just as sensitive as anything stored on a business’s own network. Each one is a decision about where a business’s data ends up, and each one is a potential target. In the LA case, the city trusted one external application to manage sensitive discovery files, and that trust became the opening an attacker needed.
Where data breach prevention breaks down for most businesses
Most businesses do not have a list of every vendor with access to their data, let alone a way to check whether those vendors are handling it responsibly. Data breach prevention often stops at the business’s own firewall and antivirus software, on the assumption that anything outside those walls is someone else’s problem or too established a platform to fail. The LA City Attorney’s office likely made a similar assumption. Officials described the compromised application as self-contained, suggesting it was treated as low risk rather than something needing the same attention as core systems.
For a small or mid-sized business, the gap is usually simpler: no one owns vendor risk at all. Contracts get signed for convenience or cost, and no one revisits them once things are working. That gap is precisely where an attacker looks first, because it’s the easiest way into an otherwise well-run business.
How managed IT security in Bakersfield closes the gap
Closing this kind of gap is a practical part of California cyber security for small and mid-sized businesses, not a one-time fix. Grapevine MSP builds its cyber security services around that idea: reviewing where sensitive data lives outside a business’s own systems, not only inside them, and monitoring those points as carefully as the core network.
That oversight also extends to the cloud tools a business relies on daily. As a Tier 1 Cloud Solutions Provider, Grapevine MSP’s cloud services team works directly with Microsoft to manage access and permissions within Microsoft 365, rather than leaving those settings on default. Combined with proactive IT support that monitors for unusual activity around the clock, this approach means a compromised vendor tool is more likely to be caught early, rather than discovered only after the data is already public.
None of this makes a business immune to every attack. It does mean fewer blind spots and a faster response when something does go wrong.
Steps to strengthen cyber security for small businesses today
A few practical steps can meaningfully reduce this kind of exposure without a large budget or a full security overhaul:
- List every vendor and software tool that can access business data, even tools that feel low-risk, like file-sharing or scheduling platforms.
- Ask new and existing vendors directly how they protect data and how quickly they would notify a business if something went wrong.
- Turn on multi-factor authentication everywhere it is available, including third-party tools, not just core business systems.
- Review who still has access to old vendor accounts and platforms, and remove access that is no longer needed.
- Know the notification obligations under California law. Under SB 446, effective January 1, 2026, businesses must notify affected California residents within 30 days of discovering a breach involving personal information. If more than 500 residents are affected, the California Attorney General’s office must also be notified within 15 days of consumer notification.
These steps do not require replacing existing systems. They require knowing where data sits outside the business and treating that as seriously as anything inside it.
The LA City Attorney’s office likely believed its most sensitive systems were secure. The breach happened somewhere else, in a tool that felt routine. That is the pattern worth watching for California cyber security, wherever a business sits in the San Joaquin Valley or beyond.
If it has been a while since anyone reviewed where your business’s data lives, a discovery call with Grapevine MSP is a straightforward way to find out and to see where the gaps are before an attacker does.
Frequently asked questions
Is my small business exempt from California’s data breach law?
No. California’s data breach law applies to any business handling residents’ personal information, regardless of size. Under SB 446, effective January 1, 2026, notice is required within 30 days of discovery.
Is my business liable if a vendor gets breached?
It depends on the contract and the data involved, but using a vendor doesn’t remove a business’s own responsibility to protect that data under California law.
What counts as a third-party data breach?
A third-party breach happens when an attacker reaches a business’s data through a vendor or software platform instead of the business’s own network, the same pattern behind the LA City Attorney case.

