District of Columbia Housing Authority Listed by interlock Ransomware Group: What Was Exposed & What To Do
The District of Columbia Housing Authority was listed by the Interlock ransomware group on July 16, 2026, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; check whether your information was exposed and consider taking protective steps.
What happened
The listing appeared on July 16, 2026. The District of Columbia Housing Authority was added to the leak site maintained by the interlock ransomware group. The group states that internal files were exfiltrated during a ransomware attack and offers 1.6 TB of material for sale. No independent confirmation of the data volume or the circumstances of the compromise has been made public. The number of people whose information may be involved remains undisclosed.
The group behind it: interlock
Interlock is a ransomware operation that targets organizations across multiple sectors. Its documented pattern involves gaining access to networks, encrypting systems, and copying data before demanding payment. The group maintains a public leak site where it lists victims and threatens to publish or sell stolen material when negotiations fail. Earlier activity attributed to the same actor has included similar claims against government and public-service entities.
About District of Columbia Housing Authority
The District of Columbia Housing Authority administers federally funded and locally supported housing programs for District residents. Its responsibilities include processing applications, verifying eligibility, managing tenant records, and maintaining databases that contain identifying information and financial details. Organizations of this type routinely hold large volumes of sensitive personal data because they assess household income, citizenship or residency status, and housing needs over extended periods.
What data was at risk
The only data type named in connection with the incident is internal files exfiltrated during the ransomware attack. The exact contents of those files have not been independently verified. Housing authorities typically maintain tenant applications, income documentation, identification records, and contact information, but whether any of these categories were included in the claimed exfiltration is unconfirmed.
Why it matters
Unauthorized access to housing-authority records can create long-term administrative and financial complications for affected residents. Files that contain personal identifiers and financial details may be used for identity-related fraud or targeted scams. For the agency itself, the incident adds operational strain at a time when it must continue delivering housing services to District residents.
Were you affected?
Begin by contacting the District of Columbia Housing Authority directly to ask what information, if any, may have been involved and what steps the agency recommends. Review bank and credit accounts for unusual activity and consider placing a fraud alert with one of the major credit bureaus. Readers can also run a free exposure scan of their email address against known breach data to check for prior appearances of their information.
- Request confirmation from the Housing Authority about any notification process.
- Monitor statements from financial institutions and government benefits programs.
- Use a reputable breach-checking service to test whether your email has appeared in past incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Centre for Newcomers Listed by interlock Ransomware GroupParagon Store Fixtures Listed by interlock Ransomware GroupBorger ISD Listed by interlock Ransomware GroupKent District Library Listed by interlock Ransomware GroupLatest breaches
Publicly posted by interlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.