Cyber Incident Victim: Miami-Dade Police Department
Date:
Feb 2020
Location:
United States of America
Summary
A ransomware attack targeted the North Miami Beach Police Department, prompting immediate system shutdowns by IT personnel upon discovery. The department engaged federal agencies including the FBI and U.S. Secret Service, alongside the Miami-Dade Police Department and third-party forensic experts, to investigate the incident's scope and objectives. Public safety operations remained uninterrupted, with no initial evidence of impact on other city services or departments. Authorities conducted ongoing analysis to determine potential unauthorized access to personal data of residents, employees, or vendors. No threat actors claimed responsibility for the attack at the time of reporting.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On February 4, 2020, the North Miami Beach Police Department identified a ransomware attack affecting its computer systems. Information technology personnel within the department discovered the intrusion and promptly initiated containment measures by shutting down impacted systems. The department immediately notified federal law enforcement agencies, including the Federal Bureau of Investigation and U.S. Secret Service, as well as the Miami-Dade Police Department for investigative support. City officials confirmed no disruption to public safety operations occurred, with police services continuing normal response to citizen calls and maintaining street patrols. Preliminary assessments indicated the ransomware exclusively affected police department systems, with no immediate evidence of compromise in other municipal departments or city services. The city emphasized uninterrupted municipal operations beyond the police department's technical systems during the incident response phase.

Authorities launched a multi-agency investigation involving federal partners, Miami-Dade Police Department, and third-party forensic experts to determine the attack's origin, scope, and objectives. The investigation included analysis to identify whether unauthorized access or acquisition of personal data belonging to residents, employees, or vendors had occurred. No ransomware group claimed responsibility for the attack at the time of reporting, with Maze Team—active in other Florida attacks—not listing North Miami Beach on their leak site. The city maintained operational continuity through the incident while withholding additional details pending investigation outcomes. This event occurred amid a broader pattern of ransomware attacks targeting Florida municipalities throughout the preceding year, though attribution to specific threat actors or campaign linkages remained unconfirmed.
