CSIDB logo
Incident

Pace Center for Girls

Incident posture

Attack window
Dec 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-13 00:00

Linked entities

Victim
Pace Center for Girls
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Pace Center for Girls experienced unauthorized access to its IT infrastructure, potentially exposing sensitive student and guardian information including names, addresses, dates of birth, Florida Department of Juvenile Justice identification numbers, enrollment details, behavioral health data, and parent/guardian names. The organization engaged cybersecurity experts to secure systems and enhance protective measures, while advising affected individuals to monitor for fraudulent activity through credit bureaus; the incident impacted up to 18,300 individuals and was reported to federal authorities.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Unauthorized individuals accessed certain infrastructure systems at Pace Center for Girls, a Jacksonville, Florida-based education program serving at-risk adolescent girls, during an incident detected in the week of December 13, 2021. The organization's subsequent investigation confirmed in January 2021 that attackers had gained access to portions of its IT infrastructure containing sensitive student information. While the exact intrusion timeline wasn't disclosed, the breach exposed personal data of current and former students including full names, physical addresses, telephone numbers, dates of birth, and Florida Department of Juvenile Justice identification numbers. Educational records including enrollment data and behavioral health information were also compromised, along with parent/guardian names. The organization did not specify whether data exfiltration occurred or identify the intrusion method used by the attackers.

In response to the security breach, Pace Center for Girls engaged a third-party cybersecurity firm to assist with network remediation and security enhancements. The organization implemented measures to secure both network access and physical computer systems while conducting assessments of existing data protection controls and gateway security infrastructure. Officials committed to implementing additional security measures as needed to prevent future unauthorized access. The incident potentially affected up to 18,300 individuals, whom the organization advised to place fraud alerts with major credit bureaus Experian, Equifax, and TransUnion. Pace Center for Girls reported the breach to the U.S. Department of Health and Human Services Office for Civil Rights, though no evidence of actual or attempted misuse of compromised data had been identified at the time of notification.

Sources

Sources available to members: 1 source.

CSIDB