City of Seal Beach and Seal Beach Police Department Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The City of Seal Beach and Seal Beach Police Department were listed by the Qilin ransomware group on January 11, 2026, following the exfiltration of internal files. Individuals who may have interacted with the city or police department should review any notices or alerts issued and take appropriate protective steps.
What happened
The only confirmed public information is the appearance of the City of Seal Beach and Seal Beach Police Department on the Qilin leak site on January 11, 2026. The group claims to have exfiltrated internal files during a ransomware attack. No official statement from the city has disclosed the date of the intrusion, the method of access, the volume of data involved, or whether any ransom demand was received or met. The number of individuals whose information may be affected is also not publicly reported.
Who is qilin?
Qilin is a ransomware group that has conducted operations against organizations in multiple countries. Like other groups in this category, it typically combines encryption of victim systems with the removal of data, then uses a leak site to pressure organizations that do not pay. The group’s listings serve as its public claim of responsibility; independent verification of the data’s authenticity or completeness is rarely available at the time of posting.
City of Seal Beach and its sector
The City of Seal Beach is a municipal government in Orange County, California, responsible for local services that include law enforcement through the Seal Beach Police Department. Local governments maintain databases that support permitting, utility billing, public-safety records, and resident interactions. A successful intrusion at this level can affect both administrative continuity and the privacy of people who rely on those services.
What data was at risk
The listing refers only to “internal files.” No inventory of specific data types has been published by the city or verified by investigators. Municipal systems commonly contain names, addresses, dates of birth, contact information, and records of interactions with city departments or police. Until the city releases a detailed notice or an official investigation report, the precise categories of information involved remain unconfirmed.
The real-world impact
Residents may face increased risk of targeted scams, identity misuse, or unwanted disclosure of personal circumstances if files containing their information are later circulated. For the city, the incident can produce operational disruption, legal and regulatory review, and costs associated with restoring systems and notifying affected individuals. These outcomes depend on factors that have not yet been disclosed, including the sensitivity of the files and whether the data has been further distributed.
What to do if you're exposed
Individuals who live or work in Seal Beach can place fraud alerts with credit bureaus, review bank and benefits statements for unusual activity, and change passwords on city-related accounts. Using unique passwords and enabling multi-factor authentication on important services reduces the chance that exposed credentials can be reused elsewhere. Readers can also run a free exposure scan of their email address against known breach data to check whether their information has appeared in previously published incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
1-800-Dentist Hit by Qilin Ransomware, Health Data of Millions ThreatenedShipping Association of NY and NJ Listed by qilin Ransomware GroupCentral Florida Cosmetic & Family Dentistry Listed by qilin Ransomware GroupAir Conditioning Florida & Mrdsllc & RTE Stucco & MR Drywall Services Listed by qilin Ransomware GroupLatest breaches
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.