CSIDB logo
Incident

Florida Keys Community College

Incident posture

Attack window
May 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-29 00:00

Linked entities

Victim
Florida Keys Community College
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Florida Keys Community College experienced a data breach stemming from a phishing campaign that compromised multiple employee email accounts over several months. Unauthorized access to these accounts potentially exposed sensitive personal and medical information, including names, addresses, Social Security numbers, passport details, and login credentials. The institution responded by securing affected accounts, notifying impacted individuals, and offering complimentary identity protection services. Security enhancements such as multi-factor authentication for all email accounts were implemented to prevent future unauthorized access.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Florida Keys Community College discovered suspicious activity involving an employee email account on October 19, 2018, triggering an immediate investigation with third-party forensic experts. The investigation revealed unauthorized access to multiple employee email accounts resulting from a phishing campaign, with compromised credentials enabling intruders to maintain access between May 5, 2018, and November 5, 2018—a six-month intrusion window. Forensic analysts conducted manual and automated reviews of affected accounts to identify exposed sensitive data, completing this assessment by January 7, 2019. During this period, attackers potentially accessed personal information including names, addresses, dates of birth, Social Security numbers, passport details, medical records, and account credentials. The College began notifying impacted individuals after confirming their identities and verifying contact information, though the exact number of affected parties wasn't disclosed in public statements.

Upon confirming the breach scope, the College secured compromised employee accounts and initiated regulatory notifications as required by law. Response measures included establishing a dedicated assistance hotline operational weekdays from 9:00 a.m. to 6:30 p.m. EST and offering 12 months of complimentary identity protection services to victims. Institutional remediation focused on enhancing email security through mandatory Multi-Factor Authentication implementation across all accounts to prevent future credential-based compromises. The College maintained its Key West, Florida address (5901 College Road) as a contact point for written inquiries regarding the incident. No evidence suggested misuse of exposed data prior to containment, though the extended access period created significant exposure risk for individuals whose sensitive identifiers resided in breached email accounts.

Sources

Sources available to members: 1 source.

CSIDB