Jacksonville Beach said ransomware attack exposed data on about 49,000 people
- Organization
- City of Jacksonville Beach, Florida
- Exploit
- Ransomware
- Industry
- Municipal Government
The City of Jacksonville Beach, Florida disclosed in March 2024 that a ransomware attack discovered at the end of January had exposed personal information belonging to tens of thousands of people.
The city said it began experiencing information system problems on or about January 29, 2024. Its investigation determined that certain files were subject to unauthorized access and that information may have been taken from the network between January 22 and January 29, 2024. Mayor Christine Hoffman put the number of potentially affected individuals at 48,949.
According to the city's notice of data security incident, the exposed records could include names, Social Security numbers, driver's license numbers and bank account information. Those affected were city employees and customers of Beaches Energy Services, the municipal utility. The attack knocked out the city's email system and forced staff to accept energy payments in person, although emergency and waste services continued to operate.
The LockBit ransomware group claimed the attack in February 2024 and listed the city on its leak site. Florida law prohibits local governments from paying ransoms, and the city did not pay. Jacksonville Beach said it secured its systems, reviewed its security policies, added protective measures, notified state and federal regulators and began mailing notices to affected individuals. It also set up a dedicated help line and worked with federal law enforcement on the investigation.