Cyber Incident Victim: GEO Group
Date:
Aug 2020
Location:
United States of America
Summary
A ransomware attack targeted a company operating private prisons and immigration detention facilities, compromising personal and health information of inmates, residents, and employees across multiple sites including correctional centers in Florida, Pennsylvania, and California. Exposed data included names, Social Security numbers, medical records, and other sensitive details. The organization implemented containment measures, restored systems without clarifying whether backups or ransom payments were involved, and notified affected individuals. While downplaying the incident's material impact in SEC filings, the breach impacted a limited portion of its global network spanning facilities across four countries. Following disclosure, the company experienced a significant stock price decline.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On August 19, 2020, GEO Group, a private operator of correctional and immigration detention facilities across the United States, Australia, South Africa, and the United Kingdom, experienced a ransomware attack compromising personal and health information of inmates, residents, and employees. The breach affected data from the South Bay Correctional and Rehabilitation Facility in Florida, a youth facility in Marienville, Pennsylvania, and a now-closed California facility. Exposed information included names, addresses, dates of birth, Social Security numbers, employee ID numbers, driver’s license details, medical treatment records, and other health-related data. GEO Group activated containment and remediation protocols to isolate the incident, restore affected systems, and strengthen network security infrastructure. The company confirmed data recovery but did not disclose whether restoration relied on backups or ransom payments to decrypt files.

GEO Group notified the U.S. Securities and Exchange Commission of the breach on August 18, 2020, asserting the incident would not materially impact business operations or financial performance. The attack compromised only a limited segment of GEO’s network, which supports 123 facilities globally. The company initiated data breach notifications to all affected individuals, detailing the scope of exposed information. U.S. government contracts constituted over 50% of GEO’s 2019 revenue, as reported in its SEC 10-K filing. Following the breach disclosure, GEO Group’s stock price declined 14% from $9.76 to $8.38 within one trading day. No operational disruptions or additional facility impacts were reported beyond the confirmed locations.
