The Anchorage Police Department (APD) took multiple containment steps after being notified of a security incident affecting its third-party technology service provider, Whitebox Technologies, a data migration firm. After Whitebox alerted APD to the incident on January 7, the city’s IT department shut down relevant APD servers and disabled the vendor and all third-party service provider access as a precaution while the investigation proceeds.
APD stated there was no evidence its internal systems were compromised or that APD data was acquired by the threat actor, but it is continuing heightened monitoring for unusual activity and implementing additional protective measures. Officials also reported overseeing the deletion and removal of remaining APD data from the provider’s servers and said they would notify potentially impacted individuals if warranted; as of reporting, no ransomware group had claimed responsibility and Whitebox had not publicly commented despite requests for information.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
APD publicly stated that it had found no evidence its own systems were compromised or that APD data was acquired by the threat actor, while continuing monitoring and protective measures as the provider-led investigation proceeded.
After the notification, the City of Anchorage IT department shut down relevant APD servers, disabled vendor and other third-party access, and oversaw deletion or removal of remaining APD data from Whitebox's servers as containment measures.
Data migration firm Whitebox Technologies alerted the Anchorage Police Department on January 7 that it had experienced a security incident affecting one of APD's technology service providers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.