On January 11, 2026, the City of Seal Beach, California, appeared on the leak site of the devman ransomware group, with attackers claiming to have stolen and exfiltrated more than 300 GB of internal government files including official documents and property deeds.
Watch sealbeachca.gov
Get alerted the next time sealbeachca.gov files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about sealbeachca.gov’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting indicates the devman group listed sealbeachca.gov as a victim and posted proof of the theft. The exposed material consists of internal city records rather than a mass dump of resident names and Social Security numbers. Available reporting describes the data as government documents, deeds, and additional unspecified files totaling over 300 GB. The exact number of residents or employees whose personal information is contained in the files remains unknown. No evidence has surfaced that the attackers have begun selling or publicly dumping the full dataset.
Why This Matters for You and Your Family
When a city government loses control of deeds, permits, and internal correspondence, the information can be used to target homeowners, small businesses, and anyone whose records are stored in those systems. Property deeds often list full names, addresses, and sometimes dates of birth or spouse details. Once that data leaves secure city servers, it can appear on data-broker sites, fraud forums, or in targeted phishing campaigns. For ordinary families this means higher risk of identity theft, mortgage fraud, or unwanted contact from scammers who now know exactly where you live and what you own. Even if your name is not on a deed, family members listed on permits, licensing records, or employee documents can still be exposed.
The Doxxing and Identity-Chain Risk
Ransomware leaks rarely stop at one dataset. A single government file containing an email address or phone number can be cross-referenced with breached gaming accounts, social-media handles, and consumer records to build a complete profile. Public reporting on similar incidents shows these chains frequently lead to doxxing, swatting, or account takeovers. Credential leaks like this one cascade into gaming platforms where children often reuse passwords or email addresses tied to family identities. The result is a widening web that can expose every member of a household long after the original breach is forgotten.