
Credit: Unsplash
Los Angeles just lived through the worst six months in its cybersecurity history, and almost nobody got in through the front door.
In March, a pro-Iranian group later linked by researchers to Iran’s Ministry of Intelligence and State Security breached L.A. Metro, wiping data, forcing the agency to review roughly 1,400 servers before restoring access, and knocking out arrival screens and TAP card reloads for riders across the county. Days later, the extortion gang WorldLeaks listed the City of Los Angeles on its dark-web leak site. By April, 7.7 terabytes of sensitive LAPD records — 337,000 files including officer personnel histories, internal affairs investigations, and unredacted criminal complaints naming witnesses — were available for download. In June, L.A. County’s Department of Public Social Services notified benefits recipients that their Social Security numbers and case files had been exposed.
Here is the detail that should reorder how every institution in this city thinks about security: the LAPD leak did not involve LAPD systems. The department said so itself. The breach hit “a digital storage system” belonging to the City Attorney’s Office — which a spokesperson described as “a third-party tool.” Reporting later revealed the file-sharing system wasn’t even password-protected.
The most damaging municipal breach in Los Angeles history was, at its core, a vendor problem.
The perimeter you don’t control
This is not an L.A. quirk. It is the defining pattern of modern cybercrime. Verizon’s 2026 Data Breach Investigations Report found third-party involvement in breaches surged 60% year over year and now appears in 48% of all confirmed incidents. Nearly half the time, the weak point isn’t the organization that gets the headline — it’s a supplier, a SaaS tool, a contractor, an API someone connected years ago and forgot.
L.A. keeps proving the statistic. LAUSD, the nation’s second-largest school district, has been burned repeatedly through its supplier ecosystem: the Illuminate Education breach in 2022, the Snowflake incident in 2024, and a breach at Kokomo Solutions — the vendor running the district’s student telehealth app and anonymous safety tip line. In June, the FTC finalized a 10-year consent decree against Illuminate, grounded specifically in the company’s failure to control vendor access to more than 10 million students’ personal information. The Automobile Club of Southern California, founded by Los Angeles motoring enthusiasts in 1900, disclosed a breach this March that originated at a driving-school software vendor most members have never heard of. Woodland Hills-based Farmers Insurance lost data on 1.1 million customers through a third-party platform in the industry-wide Salesforce attacks.
And the attackers are getting faster. CrowdStrike documented a 340% increase in AI-assisted intrusion attempts versus 2024. Anthropic disclosed the first documented case of a largely autonomous, AI-orchestrated espionage campaign. Mandiant found that more than a quarter of new vulnerabilities are now exploited within 24 hours of disclosure. The window between “a vendor has a flaw” and “your data is on a leak site” has collapsed from months to hours.
The industry that grew up to fix this
Corporate America saw this coming, which is why an entire discipline — the security review — has professionalized over the past five years. Before a Fortune 500 company connects a new vendor to its systems, that vendor faces hundreds of questions about encryption, access controls, incident response, and subprocessors. For decades, that work defaulted to Big Four consultancies: six-week engagements, six-figure invoices, a binder at the end. It is tedious, unglamorous work. It is also, increasingly, the difference between a headline and a non-event.
San Francisco-based SecurityPal has become one of the defining companies of the modern version of that discipline — the AI-era alternative to the consultancy model, described by its founder and CEO Pukar Hamal as “Palantir for security reviews — expert humans and AI working together to accelerate enterprise security assessments,” as he told VentureBeat. Its customer roster, Forbes reported, includes OpenAI, Figma, and Airtable, alongside Fortune 500 companies; assessments that once took weeks now turn around in roughly 24 hours, and buyers using the platform to vet their own suppliers report vendor reviews up to 125 times faster — fast enough, crucially, to evaluate every vendor instead of sampling a risky few.
The engine behind that speed is a story in itself. SecurityPal runs a 24/7 command center in Kathmandu, Nepal, staffed by a 240-person analyst team that pairs with the company’s AI — a workforce of hundreds handling the trust infrastructure of Silicon Valley from the foothills of the Himalayas. Hamal, who was born in Nepal and emigrated to New York as a child, has spent years building that hub into something larger than one company: a tech ecosystem he coined “Silicon Peaks,” now spanning dozens of firms as Nepal’s IT exports crossed $1 billion. “If I retired, this is still the thing I would want to be doing, bringing Silicon Valley to Kathmandu,” he told Forbes.
The company, backed by $21 million from investors including Craft Ventures and Andreessen Horowitz partner Martin Casado, built all of it on a blunt market truth Hamal articulated to Forbes: “If you create risk for companies today, you’re going to lose the deal.” That sentence explains why the private sector fixed this problem. Risk became commercially disqualifying. A vendor that can’t prove its security posture doesn’t get the contract; a buyer that doesn’t check gets breached and sued. The incentive loop closed, and companies like SecurityPal became the infrastructure of trust between businesses — assurance management. “The faster, higher-quality assurance that you can deliver, and the faster, higher-quality assurance that you can get, puts you on the best footing for the future,” he told Security Current.
The government gap
Now hold that standard up against Los Angeles government, where a system holding 337,000 police files sat online without a password.
The uncomfortable truth is that nothing about local government procurement is state-of-the-art, and security review is no exception. Agencies buy software through processes designed decades ago, hold vendors to boilerplate “reasonable security” contract language, and rarely re-assess after onboarding. The private sector treats vendor assurance as continuous; government treats it as a checkbox — when it exists at all. Black Kite’s 2026 research found breach disclosure now lags detection by an average of 117 days, meaning agencies that don’t proactively assess their vendors are structurally the last to know.
The stakes are no longer abstract. Los Angeles is mid-World Cup, with a quarterfinal at SoFi Stadium and federal agencies warning that Iranian-linked actors are targeting exactly the municipal infrastructure — water, energy, transit — that host cities depend on. The Olympics arrive in 2028. Every one of those systems runs on a web of contractors, integrators, and software vendors that no adversary needs to bypass, because too often, no one is checking them.
The tools exist. The playbook exists. An entire industry — the one Fortune 500 boardrooms now consider indispensable — exists. Hamal told Security Current his company is built “so that we’re around for our customers, not just for over the next year, but for the next five, ten years and beyond.” Los Angeles should be planning on the same horizon. The next WorldLeaks post, the next Ababil of Minab, the next unnamed vendor with an unlocked door — they’re not waiting for the city to modernize its paperwork.
The attack surface is the org chart of everyone you’ve ever signed a contract with. It’s time L.A.’s government read it that way.