Skip to content

D.C. Housing Authority cyberattack disrupts systems

Summary

District of Columbia Housing Authority logo

DCHA discovered a cybersecurity incident June 28, 2026, shut down its network and restored services in phases. It confirmed compromised sensitive information July 17 and announced normal operations for every department beginning July 20; no later disruption was found by August 3, so operations are presumed resolved. Interlock’s ransomware and 1,660 GB theft claim remains unverified.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Data extortion

    Threats to publish or sell stolen data without evidence of encryption.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Website unavailable

    A public-facing website was unavailable, disabled, or inaccessible.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Backlog created

    The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

The District of Columbia Housing Authority discovered a cybersecurity incident affecting its network environment on June 28, 2026. DCHA’s initial detailed statement said it immediately shut down the environment, engaged cybersecurity experts and law enforcement and began restoring services within a remediated network. The public record does not establish when malicious activity began, so June 28 is the discovery and containment date rather than a confirmed intrusion start.

On July 17, DCHA confirmed that investigators found a limited subset of agency data, including sensitive information, had been compromised. DCHA said it found no evidence that the sensitive information had been misused and would offer customers credit monitoring and identity-theft assistance. It did not identify the affected data categories, people, records or systems.

Interlock separately claimed DCHA on its dark-web leak site. Daily Security Review reported the listing, while BreachSense attributed a claimed 1,660 GB leak to Interlock. DysruptionHub treats this as an external threat-actor claim, not DCHA-confirmed attribution or proof of the claimed theft volume, ransomware encryption or a ransom demand.

Operational significance

The incident disrupted DCHA’s website and email, left staff without file access and paused online activities. DysruptionHub’s initial reporting documented that offices and customer service centers remained open, residents could seek help by phone or walk-in service and landlord payments were expected to continue. The disruption therefore affected core housing-administration systems and public access without producing a complete agency shutdown.

Recovery proceeded in stages. DCHA’s July 10 operations update said the call center returned to normal July 8, customer centers provided full service with limited staff, RentCafe was available and employees were regaining computer access in phases. Customers could expect slower responses, and non-urgent matters would wait until the network and systems were fully restored. A July 15 update said a temporary website had launched July 8, customer centers and the call center were providing full service, staff were handling new and previously filed inquiries and employee laptops were being analyzed before returning online.

Disclosure posture

DCHA’s disclosures evolved from a general system-disruption notice to detailed recovery updates and confirmation of compromised sensitive data. The agency identified cooperation with law enforcement, the D.C. Office of the Chief Technology Officer, internal IT staff and outside cybersecurity experts. It also advised customers to monitor accounts and credit reports while promising additional credit-monitoring information.

The agency has not published the promised enrollment details, affected-data categories, notification population or final forensic findings. Its July 17 statement said more information would be shared when the investigation was complete.

Current status

DCHA said July 17 that normal operations would resume for every department on July 20. By August 3, its regular website and customer portal were functioning, and the agency had published routine updates after the announced return date. No later operational disruption was found. DysruptionHub therefore assesses that material operational impact is presumed resolved, while leaving the exact restoration date and final recovery confirmation unresolved. The continuing forensic and customer-protection work does not by itself indicate continuing operational disruption.

Confidence and uncertainty

Confidence is high that malicious or unauthorized cyber activity caused material disruption because DCHA directly confirmed the cybersecurity incident, network shutdown and phased restoration. Confidence is high that sensitive data was affected because DCHA confirmed that finding, but the exact confidentiality impact remains only partly defined.

Confidence is medium that the incident involved Interlock-linked ransomware or data extortion. The actor claim aligns in time with DCHA’s confirmed incident and data compromise, but DCHA has not corroborated Interlock, ransomware, encryption, exfiltration volume, a demand or payment. The leak-site listing is the only established extortion indicator; no public leak threat, sample, countdown, negotiation or payment was found.

Analytic gaps

The public record does not establish the initial-access vector, exploited vulnerability, compromised account or host, malware family, persistence, dwell time, encryption, backup impact or restoration method. It also does not establish which sensitive-data categories were affected, how many people or records were involved, whether data was copied or removed, whether any claimed dataset is authentic, or whether misuse later occurred.

A completed forensic report, individual notification, regulator filing, credit-monitoring notice, law-enforcement statement, direct actor evidence or retrospective restoration confirmation could materially change the assessment.

Threat actor and claim

Listed as: District of Columbia Housing AuthoritySource: otherPublished: Discovered:

Claim details

Interlock claimed the District of Columbia Housing Authority on its leak site. Daily Security Review reported the listing, and BreachSense reported a claimed 1,660 GB volume. DCHA confirmed only that a limited subset of data including sensitive information was compromised; it did not confirm Interlock, the claimed volume, data theft, ransomware encryption or a demand.

Organizations involved

Impacted locations

Sources

District of Columbia Housing Authority cyber incident disrupts website, files

DCHA said a cybersecurity incident disrupted website and email access. A D.C. Council office said DCHA described an active cyberattack, staff lacked file access, online activities were paused and customers were directed to phone or walk-in assistance. Landlord payments were expected to proceed, while ransomware, a demand, data access and attribution were not established at publication.

DCHA system disruption notice

DCHA stated that it was experiencing a system disruption due to a cybersecurity incident, that website and email access were affected, and that offices remained open with customer service available by phone.

Statement: DCHA Cybersecurity Incident

DCHA said it discovered a cybersecurity incident over the June 27–28 weekend, immediately shut down its network environment and engaged cybersecurity experts and law enforcement. Website and email were unavailable, but offices, urgent transactions, inspections and expected landlord payments continued through alternate arrangements while restoration proceeded.

DCHA's Current Operations Status

DCHA said employees were regaining computer access in phases, the call center returned to normal July 8, customer centers offered full service with limited staff July 9 and RentCafe was available. Response times remained slower, and non-urgent matters would wait until the network and systems were fully restored.

DC Housing Authority Update Regarding Cybersecurity Incident

DCHA specified that it discovered the incident and shut systems down June 28. A temporary website launched July 8, customer centers and the call center were providing full services with possible delays, forensic work remained active and employee laptops were being analyzed before returning online.

DC Housing Authority Cybersecurity Incident Update

DCHA confirmed that a limited subset of agency data, including sensitive information, was compromised and said it found no evidence of misuse. It announced credit monitoring and identity-theft assistance, identified law-enforcement and OCTO involvement, said forensic work continued and planned normal operations for every department on July 20.

Interlock Hits DC Housing Authority; Play, Nova Post New Victims

Daily Security Review reported that Interlock listed the District of Columbia Housing Authority on its dark-web leak site during the July 16–17 window. It said no ransom amount was disclosed and DCHA had not confirmed the actor’s claim.

District of Columbia Housing Authority Data Breach in 2026

BreachSense identified dchousing.org as an Interlock claim discovered July 17 and reported a claimed leak size of 1,660 GB. DCHA did not confirm the actor, claimed theft volume or authenticity of any dataset.

See something that needs correction?

Signed-in members can report an error, update, or missing source.