Cyber Incident Victim: Florida Department of Business and Professional Regulation
Date:
Oct 2020
Location:
United States of America
Summary
A Florida state regulatory agency experienced malicious cyber activity causing extended system outages and disruptions to online services. The incident prompted an investigation by state law enforcement, though no evidence of compromised personally identifiable information was identified. While public-facing services were restored, internal operations faced continued challenges as the agency worked to eliminate residual threats. This event was unrelated to an earlier technical failure in the voter registration system attributed to server misconfigurations rather than malicious actors.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On October 7, 2020, the Florida Department of Business and Professional Regulation (DBPR) detected malicious activity within its computer systems, triggering an immediate operational disruption. The incident caused extended outages across the department's digital infrastructure, with systems remaining offline through the following Monday. These outages disrupted public access to the agency's online services, which handle licensing and regulatory functions for multiple business sectors statewide. While public-facing services were restored by October 20, internal system resources continued experiencing intermittent disruptions as agency personnel worked to eliminate residual threats. The Florida Department of Law Enforcement (FDLE) initiated an investigation into the incident at DBPR's request, though the origin and nature of the malicious activity remained unidentified at the time of reporting. Secretary Halsey Beshears publicly confirmed the investigation but provided no specifics regarding attack vectors or potential threat actors.

DBPR's forensic review found no evidence that personally identifiable information—including Social Security numbers, addresses, or other sensitive data—was compromised during the incident. The agency maintained this assessment throughout the immediate response phase. This event occurred independently of an unrelated October 5 technical failure in Florida's voter registration system, which state officials attributed to misconfigured servers rather than malicious cyber activity. Technicians resolved the voter system disruption through server reconfiguration and capacity expansion within the same operational timeframe. Both incidents caused temporary service interruptions across separate government systems, though only the DBPR outage involved confirmed malicious activity requiring law enforcement intervention.
