ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

California's largest labour union suffers a LockBit ransomware attack

California-based labour union SEIU Local 1000 said a major cyber incident that occurred in January enabled threat actors to encrypt certain systems in its internal network.

 

Service Employees International Union (SEIU) Local 1000 is one of the largest labour unions in California, representing almost 100,000 employees in over 2,000 worksites across the state.

 

On January 19, the notorious LockBit ransomware group claimed that it infiltrated the SEIU Local 1000 network and exfiltrated around 308GB of data. The stolen data included employee Social Security numbers, salary information, financial documents and more.

 

 

Acknowledging the ransomware group’s claims, the labour union said that on January 18, it experienced a “network disruption by an outside actor.” In a social media post, it said that it launched an investigation with assistance from external cyber security experts to understand the nature and scope of the incident.

 

“As we investigated the incident, we learned that it was caused by certain data being encrypted. We are aware of the discussion happening on social media about the type of attack we are purported to have had and the actor by whom it was apparently done.

 

“We are currently working with outside experts to ensure ongoing network security and assist and advise as we continue to restore our operations. This incident was a criminal cyber act and is being treated as such as we assist law enforcement,” it said.

 

The labour union is in the process of determining whether any sensitive personal data has been accessed or stolen by the hacker group. If so, after identifying the affected individuals, the labour union will notify them about the incident and offer guidance on how to protect themselves from cyber crime. The organisation has also agreed to offer credit monitoring and identity protection services to individuals whose data was compromised in the data security incident.

 

“We know the attack has caused concern and also inconvenience, and we want you to know we haven’t stopped doing the work of the Union. We worked quickly to reopen our call centre, and with our dedicated staff, worked with our principal state agencies to handle ongoing bargaining issues, cases, grievances, hearings, and meetings.

 

“As we fully bring our systems back online, we have never stopped fighting for the rights of state workers. Coordinated attacks against unions come from a number of anti-worker groups, and we will not let this one distract us from the important issues that face us with the State, the budget process or any of the upcoming political primary battles. With your help and commitment, we will stay strong in the face of any adversity and will come back stronger than before,” SEIU Local 1000 added.

 

The official website of the organisation now has a banner notifying individuals about the cyber security incident and a dedicated helpline number where members can call and get their queries answered.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543