Uncategorized
8 min read

How Oakland CA Lost Over $10 Million Due to Cyber Attack

December 24, 2025 By Al Kao

Here’s the story of how a city in California came under a ransomware attack, ended up getting a class action lawsuit, and faces a staggering cost of over $10 million dollars.

In 2023, the city of Oakland California fell victim to a ransomware cyber attack. The result of the attack ended up costing the city 

What Happened? The Ransomware Attack

The cyber attack began on February 8, 2023, when the City of Oakland’s IT systems were hit by the Play ransomware group. The city was forced to shut down numerous systems to contain the infection, leading to a local state of emergency being declared.

The impact was immediate and widespread, disrupting critical city services for weeks. Municipal services, including phone lines, email, payment processing, permit issuance, and even library computers, were disabled or severely affected.

The City of Oakland refused to pay the ransom demanded by the Play group cyber attackers. As a result, in retaliation for the city’s refusal to pay, the attackers engaged in “double extortion”, leaking a massive amount of stolen data onto the dark web.

This sensitive data included the personal information (Social Security numbers, home addresses, medical data) of current and former city employees, as well as residents who had filed claims or federal benefits. The recovery process for all city systems took months, with full recovery reported in May 2023.

How Did the Attackers Do It?

Though the full details of the attack is protected information, the most common and effective cyberattack method is phishing.

It is believed that The Play ransomware group gained initial access to the city’s network after an employee fell for a phishing email. Phishing emails are highly deceptive  and a very common attack point for cyber criminals.

Once inside, the cyber attackers likely used custom tools to quickly survey and map the network, escalate their privileges, and move across the city’s systems. The cyber criminals employed their standard “Play” ransomware to encrypt city data, making systems unusable ,while at the same time, stealing sensitive data.

This kind of cyber attack is a type of “double extortion”, forcing the victim to need both the encryption key to unlock their own systems and to prevent a data leak.

How It Cost the City Over $10 Million

Since the city of Oakland refused to pay the cyber criminals, the attackers released the sensitive city data onto the dark web.

While the exact cost of the attack is still on-going and difficult to fully account for, there are already costs associated with the attack:

Remediation & Mitigation:

Oakland had to pay for forensic analysis of the attack, network segmentation, system rebuilding, and procuring new hardware/software to restore the city systems while bringing in expert cybersecurity consultants. The city budgeted $10 million, reportedly, specifically to enhance its IT security and infrastructure in the aftermath of the attack.

Class-Action Lawsuits:

Shortly after the attack and the data leak of private data of city employees and city residents, Oakland faced class-action lawsuits from over 10,000 individuals. As of 2025, the settlement that the city reached includes:

  • Up to $10,000 per person for documented “extraordinary losses” (e.g., fraud/monetary loss).
  • Up to $350 per person for “ordinary losses” (e.g., lost time, credit monitoring fees).
  • Three years of free credit monitoring services for all affected individuals.
  • $175 for Police Officers: cash payment of $175.00 regardless of whether officers experienced any fraudulent or unauthorized activity, any identifiable losses, or any identity theft.

Cybersecurity Lessons for Businesses

The lessons from Oakland’s cyber attack demonstrates the need for businesses to be proactive in securing their IT infrastructure and cybersecurity measures. These are the key lessons:

  1. Phishing Works (and It’s the Starting Point): The easiest way into a network is through human error.
  2. Double Extortion is the Norm: Ransomware isn’t just about encrypting files anymore; it’s also about stealing them. Paying the ransom may decrypt your files, but it doesn’t guarantee the attackers won’t leak the stolen data.
  3. The Cost of Inaction is Immense: Remediation, legal fees, and reputational damage far outweigh the cost of preventative security investments.

Prevention and Mitigation Steps:

Action ItemWhy It Matters
Multi-Factor Authentication (MFA)Mandate MFA because MFA is highly effective defense against credential theft via phishing. Even if a hacker steals a password, they cannot log in without a second form of verification.
Zero-Trust BackupsMaintain copies of your data on at least two different media types with one copy stored off-site and offline (air-gapped). The offline backup is your last line of defense, ensuring attackers can’t encrypt or delete all your recovery files.
Regular TrainingTrain and drill employees to recognize and report phishing, social engineering, and suspicious links. Employee training is essential to prevent cyber attackers from gaining entry.
Patch ManagementRegularly update all operating systems, software, and firmware. Attackers exploit known vulnerabilities. Automated patching is vital for closing these security gaps before they are exploited.
Network SegmentationDivide your network into smaller, isolated segments. If an attacker breaches one area (e.g., the accounting department), they are blocked from immediately reaching your most critical servers (e.g., the HR database).
Incident Response Plan (IRP)A cyber attack is inevitable, so having an IRP detailing who to call (law enforcement, legal counsel, IT firm), how to communicate, and what the step-by-step process for isolating and restoring systems is important.

Welltec Defense offers comprehensive IT and cybersecurity solutions to help ensure your company doesn’t fall into a situation like the city of Oakland, California. Whether you need to secure your IT infrastructure, connect your IT and cybersecurity processes into one efficient system, or need comprehensive training for your staff, Welltec Defense is ready to help your firm.

Sources:

Ready to harden your defenses?

Start with a comprehensive risk assessment. Our engineers will identify your vulnerabilities and build your custom shield.

Request a Risk Assessment