Accela sells the permitting and licensing software that many California cities and counties rely on behind the scenes. When an unauthorized actor broke into one of Accela’s file transfer systems, the notice letters going out don’t come from Accela. They come from your local government, and Emery | Reddy is investigating on behalf of California residents.
Accela, Inc. provides permitting, licensing, and government-technology software to city and county agencies across the country. According to a notice filed with the California Attorney General, an unauthorized actor accessed one of Accela’s secure file transfer portals and acquired copies of certain files between December 11 and December 12, 2025. Accela disclosed the breach to California regulators on September 14, 2026, roughly nine months after the intrusion.
Because Accela is a technology vendor rather than a consumer-facing company, the notice letter going out to affected individuals is written on behalf of the specific government client whose data was involved, not under the Accela name. If you received a breach notice recently from your city, county, or another local government agency, and the letter describes a software vendor’s file transfer system being compromised, this may be the incident that applies to you, even if the word “Accela” never appears in your letter.
Who We’re Prioritizing
Emery | Reddy is prioritizing outreach to California residents for this investigation, given that the confirmed disclosure to date has come through the California Attorney General’s office. If you live in California and received a notice describing this kind of incident from a government agency you interact with, we want to hear from you.
A Ransomware Group’s Claims
On December 23, 2025, a ransomware group calling itself Everest claimed responsibility for the intrusion in a posting on the dark web, stating it had obtained approximately one terabyte of internal data and threatening to publish it within a week. Emery | Reddy has not independently verified the scope of that claim, and Accela’s own notice does not confirm a specific volume of data taken. We are including it here because it is a matter of public record that a named ransomware group asserted responsibility for this incident shortly after it occurred.
What Information Was Exposed?
Accela’s notice does not specify which categories of personal information were involved. It confirms only that files were accessed and acquired from a secure file transfer portal over a two-day window. Accela has stated that the incident was limited to its own systems and that its government clients’ own systems were not directly affected.
Do You Have Legal Options?
Companies that provide software and data services to government agencies still have a legal duty to safeguard the personal information that passes through their systems. If you received a notice describing this incident, whether it named Accela directly or came from a government agency that uses Accela’s software, you may have rights and remedies under California law.
If you are a California resident who received a notice describing this incident, contact the Data Breach Attorneys at Emery | Reddy for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Companies and their vendors are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
Frequently Asked Questions
My notice letter doesn’t mention Accela. Could this still be the same breach?
Yes, possibly. Accela’s notice is issued on behalf of its government clients, so the letter you received may be written under the name of your city, county, or other local agency instead of Accela’s name. If your letter describes a vendor’s file transfer system being breached around December 2025, contact us so we can help you determine whether this is the same incident.
How many people were affected?
Accela has not disclosed a total number of affected individuals in its filing or public notice.
What information was exposed?
Accela’s notice does not itemize specific categories of personal information. It confirms only that files were accessed and taken from a secure file transfer portal between December 11 and December 12, 2025.
Has a ransomware group claimed responsibility?
A group calling itself Everest claimed responsibility on the dark web in December 2025 and said it obtained about a terabyte of data. That claim has not been independently verified and is separate from Accela’s own confirmed disclosure.
Why did it take about nine months to disclose this breach?
Accela’s notice to the California Attorney General came in September 2026, roughly nine months after the December 2025 intrusion. Accela has not publicly explained the reason for that gap.
Do I have a legal claim?
You may. Technology vendors that handle personal information on behalf of government agencies have a legal duty to protect that data. If you are a California resident who received a notice describing this incident, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.