Cyber Incident Victim: Florida Keys Community College
Date:
May 2018
Location:
United States of America
Summary
Florida Keys Community College experienced a data breach stemming from a phishing campaign that compromised multiple employee email accounts over several months. Unauthorized access to these accounts potentially exposed sensitive personal and medical information, including names, addresses, Social Security numbers, passport details, and login credentials. The institution responded by securing affected accounts, notifying impacted individuals, and offering complimentary identity protection services. Security enhancements such as multi-factor authentication for all email accounts were implemented to prevent future unauthorized access.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Florida Keys Community College discovered suspicious activity involving an employee email account on October 19, 2018, triggering an immediate investigation with third-party forensic experts. The investigation revealed unauthorized access to multiple employee email accounts resulting from a phishing campaign, with compromised credentials enabling intruders to maintain access between May 5, 2018, and November 5, 2018—a six-month intrusion window. Forensic analysts conducted manual and automated reviews of affected accounts to identify exposed sensitive data, completing this assessment by January 7, 2019. During this period, attackers potentially accessed personal information including names, addresses, dates of birth, Social Security numbers, passport details, medical records, and account credentials. The College began notifying impacted individuals after confirming their identities and verifying contact information, though the exact number of affected parties wasn't disclosed in public statements.

Upon confirming the breach scope, the College secured compromised employee accounts and initiated regulatory notifications as required by law. Response measures included establishing a dedicated assistance hotline operational weekdays from 9:00 a.m. to 6:30 p.m. EST and offering 12 months of complimentary identity protection services to victims. Institutional remediation focused on enhancing email security through mandatory Multi-Factor Authentication implementation across all accounts to prevent future credential-based compromises. The College maintained its Key West, Florida address (5901 College Road) as a contact point for written inquiries regarding the incident. No evidence suggested misuse of exposed data prior to containment, though the extended access period created significant exposure risk for individuals whose sensitive identifiers resided in breached email accounts.
