CSIDB logo
Incident

Florida Department of Agriculture and Consumer Services

Incident posture

Attack window
May 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-31 02:10

Linked entities

Victim
Florida Department of Agriculture and Consumer Services
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity breach at the Florida Department of Agriculture and Consumer Services compromised the names of over 16,000 concealed weapons permit holders and the Social Security numbers of 469 customers through its online payment system. The intrusion was detected and mitigated within 24 hours, with no financial information accessed and other exposed data deemed publicly available and non-risky for identity theft. Affected individuals were notified, and those with compromised Social Security numbers received free credit monitoring and fraud alerts. The agency's commissioner ordered a review of cybersecurity protocols, while law enforcement investigations into the incident remain ongoing.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 22, 2017, the Florida Department of Agriculture and Consumer Services (FDACS) disclosed a data breach involving its online payment system, which processed transactions for concealed weapon permits and other applications. Hackers accessed the system approximately two weeks prior, compromising the names of over 16,000 individuals who had renewed concealed weapon permits online. The breach also potentially exposed the Social Security numbers of 469 customers. FDACS detected the intrusion less than 24 hours after it occurred and promptly shut down the affected system. Spokesperson Jenn Meale confirmed the agency traced the attack’s origin to overseas actors but did not disclose the specific intrusion method or suspected perpetrators. The department emphasized that no financial information was compromised and stated any other accessed data constituted publicly available information posing no identity theft risk. Immediate mitigation efforts included system isolation and internal cybersecurity reviews.

FDACS notified all affected individuals following the breach discovery. The 469 customers whose Social Security numbers were exposed received offers for one year of complimentary credit monitoring and fraud alerts. Agriculture Commissioner Adam Putnam, then a gubernatorial candidate, ordered a comprehensive evaluation of the department’s cybersecurity protocols. Florida state law enforcement agencies initiated an investigation into the incident, though no additional details regarding investigative findings or suspect identification were released. The department reiterated its commitment to customer privacy and cybersecurity in public statements, highlighting rapid containment actions but providing no technical specifics about system vulnerabilities or long-term remediation plans beyond the initial response.

Sources

Sources available to members: 1 source.

CSIDB