LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › I.L.A. Local 1964 Listed by dragonforce Ransomware Group

HIGH severityUnverified claimHow we verify

I.L.A. Local 1964 Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 29, 2024
I.L.A. Local 1964 Listed by dragonforce Ransomware Group

Reported May 29, 2024.

HIGH
Severity
May 29, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The I.L.A. Local 1964 Listed by dragonforce Ransomware Group (reported May 29, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For members and staff connected to I.L.A. Local 1964, the appearance of the union on a ransomware group’s listing raises immediate questions about personal and workplace information. When internal files are said to have been taken, the practical stakes include possible exposure of records that unions routinely maintain about wages, benefits, and employment status—details that can be misused for fraud or unwanted contact if they circulate beyond the organization.

Public reporting on 29 May 2024 indicated that I.L.A. Local 1964 had been listed by the DragonForce ransomware group in connection with a claimed ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and further technical particulars have not been disclosed. The listing itself is a claim by the group; independent confirmation of the full scope has not been provided in the available record.

Breaking down the breach

According to the reported summary, I.L.A. Local 1964 was listed by DragonForce on or around 29 May 2024. The description states that internal files were exfiltrated in a ransomware attack. No public figures have been given for the volume of data, the exact date the intrusion began or was discovered, the initial access method, or any ransom demand. The number of individuals whose information may be involved is listed as unknown. Because these elements remain undisclosed, the incident can be described only in the limited terms that have been made public: a claimed ransomware event that included the removal of internal files, followed by the group’s decision to name the organization on its leak site.

Who is dragonforce?

DragonForce is a ransomware operation that has been documented in open sources as employing double-extortion tactics. In this model, operators encrypt systems and simultaneously copy data, then threaten to publish the stolen material if payment is not made. The group maintains a leak site where it posts victim names and, in some cases, sample files or larger archives. Public reporting on DragonForce has noted its use of affiliate-style recruitment and its focus on organizations across multiple sectors rather than a single industry. These patterns are drawn from broader, well-established accounts of the group’s activity; they do not constitute verified statements about the specific methods used against I.L.A. Local 1964. With respect to this listing, the only claim on record is that the group named the local and asserted that internal files had been taken.

I.L.A. Local 1964 and its sector

I.L.A. Local 1964 is a local of the International Longshoremen’s Association that represents workers across a range of industries and professions. Its membership has historically included people in ocean shipping, trucking and warehousing logistics, as well as nurses’ aides, dialysis technicians, building-maintenance workers, grocery-store employees, and laundry workers. Chartered in 1970, the local has for more than five decades negotiated wages, health benefits, pensions, vacations, and sick leave, and has pressed employers to maintain decent working conditions.

Labor organizations of this type typically hold membership rosters, dues records, benefit-enrollment data, grievance files, and correspondence with employers. Because the local spans both maritime logistics and service occupations, a compromise of its systems can affect people whose daily work is far removed from the waterfront yet still tied to the same bargaining unit. The consequential nature of a breach here stems from the concentration of employment-related personal information in one place and from the trust members place in their union to safeguard that information while advocating on their behalf.

What was likely exposed

The only data category named in the public record is “internal files” said to have been exfiltrated. No inventory of specific document types, file counts, or data fields has been released. Organizations such as I.L.A. Local 1964 commonly maintain membership lists, contact details, Social Security numbers or other identifiers used for benefits administration, health-plan and pension records, payroll-related information, and internal correspondence. Whether any or all of those categories were among the files taken remains unconfirmed. Readers should treat any assertion of precise contents as speculative until official notification or further verified reporting appears.

Why it matters

If employment or benefits data were among the internal files, affected individuals could face risks of identity theft, fraudulent benefit claims, or targeted phishing that references genuine workplace details. Even limited contact information can be combined with other publicly available data to craft more convincing social-engineering attempts. For the local itself, the incident can disrupt day-to-day operations, strain member confidence, and create ongoing costs related to investigation, notification, and system hardening. Because the scale remains unknown, the practical impact ranges from a contained administrative problem to a broader exposure affecting many households; the absence of confirmed numbers simply means the full picture is not yet available.

Unions occupy a position of trust with their members. When that trust is tested by a claimed data theft, the consequences are measured less in abstract technical terms and more in the concrete possibility that personal records could be used against the very people the organization exists to protect.

Were you affected?

If you are a current or former member, staff member, or beneficiary connected to I.L.A. Local 1964, monitor official communications from the local for any breach notification. Review bank and credit-card statements for unfamiliar activity, consider placing a fraud alert with the major credit bureaus, and be cautious of unexpected emails or calls that reference union business or benefits. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. These steps do not confirm or rule out involvement in this specific incident, but they provide a practical starting point while further details remain limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyI.L.A. Local 1964 security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See I.L.A. Local 1964’s full breach history →

More recent breaches

Williams Tank Lines Listed by dragonforce Ransomware GroupDecember 14, 2024FINN Listed by dragonforce Ransomware GroupDecember 14, 2024Oahu Transit Services Listed by dragonforce Ransomware GroupJune 16, 2024Seafrigo Listed by dragonforce Ransomware GroupJune 9, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the I.L.A. Local 1964 Listed by dragonforce Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by dragonforce — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram