CareerSource Palm Beach County, a Florida workforce development nonprofit, confirmed a ransomware attack by a group called thegentlemen that may have exposed personal and employment records of job seekers and employees. The exact number affected has not been disclosed. Affected individuals should monitor credit reports and consider a credit freeze immediately.
| Company | CareerSource Palm Beach County |
|---|---|
| Industry | Non-profit |
| Data Types Exposed | Full Names, Contact Information, Employment History, Social Security Numbers, Government-Issued Identification, Program Enrollment Records |
| People Affected | Not Publicly Disclosed |
| Attack Method | Ransomware |
| Regulators Notified | Not Publicly Disclosed |
What Happened in the CareerSource Palm Beach County Data Breach?
CareerSource Palm Beach County, a nonprofit workforce development organization based in West Palm Beach, Florida, has confirmed that its network was targeted in a ransomware attack. A threat actor group known as “thegentlemen” has claimed responsibility for the intrusion. This group is known for breaching organizations and then threatening to release stolen files unless a ransom is paid.
The organization notified the public about this incident in September 2026. As of now, the exact date when the intrusion first occurred has not been publicly disclosed. However, ransomware attacks like this one typically involve attackers gaining quiet access to a network well before deploying malware or announcing a breach.
Because CareerSource Palm Beach County works closely with job seekers and employers across the region, its systems likely hold sensitive personal and employment-related records. Following discovery of the incident, the organization launched an investigation to determine the scope of the intrusion. As a result, affected individuals are now left waiting for more specific details about what data the attackers accessed.
Investigations into ransomware attacks like this one often take weeks or months to complete. This is because forensic teams must trace how attackers entered the network, what files they touched, and whether data was actually copied or exfiltrated. In many similar cases, the attacker group itself provides the first public confirmation that data was stolen, which appears to be part of what happened here.
Who was affected?
The population affected by this CareerSource Palm Beach County data breach has not been publicly disclosed in terms of an exact number. Given the organization’s role, however, those impacted likely include job seekers, program participants, and possibly local employers who used its workforce services. In addition, current or former employees of the organization could also be included.
Because CareerSource Palm Beach County serves residents throughout Palm Beach County, Florida, the geographic scope of this breach is likely concentrated in that region. Still, some affected individuals may now live elsewhere. Job training and employment programs often include a wide range of participants, including younger workers and possibly minors enrolled in youth employment initiatives.
Until the organization releases an official count, affected individuals should assume they could be included if they interacted with CareerSource Palm Beach County’s programs or services. Therefore, monitoring official communications from the organization is important for anyone who has used its services in recent years.
What Information Was Potentially Exposed?
The specific categories of data taken in this incident have not been fully detailed in public reporting so far. However, based on the nature of workforce development organizations and the operations CareerSource Palm Beach County performs, certain types of personal information are commonly stored on these systems.
- Full names
- Contact information such as addresses and phone numbers
- Employment history and job application details
- Social Security numbers (potentially, given standard workforce program intake records)
- Government-issued identification details
- Program enrollment and case management records
If Social Security numbers or identification details were indeed included, affected individuals could face a heightened risk of identity theft. Criminals can use this type of data to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. This is especially concerning because this kind of fraud can go undetected for months.
In addition, employment and case management records can be used for targeted phishing scams. For example, a scammer could pose as CareerSource Palm Beach County staff and request additional personal details from a former program participant. Because this data can reveal specific interactions someone had with the organization, phishing attempts built around it can feel very convincing.
What is the company doing?
In response to the ransomware attack, CareerSource Palm Beach County has taken steps to investigate the intrusion and assess its impact. This typically includes engaging cybersecurity specialists to determine how the attackers gained access and to close off any remaining vulnerabilities in the network.
Moving forward, the organization is expected to notify individuals whose information was confirmed to be involved, as required under Florida law. Impacted individuals should watch for official letters or emails from CareerSource Palm Beach County describing the specific data involved and any protective services being offered, such as credit monitoring.
Because investigations of this kind are ongoing, additional information may be released as it becomes available. In the meantime, affected individuals should treat any communication claiming to be from the organization with some caution, and verify its authenticity through official channels before providing any personal information.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone who may have interacted with CareerSource Palm Beach County should regularly check their credit reports for unfamiliar activity. This includes new accounts, unexpected credit inquiries, or changes to your personal information that you did not authorize.
You can request a free credit report from each of the three major credit bureaus at least once per year. Because early detection makes a real difference, reviewing these reports every few months is a smart habit, especially in the months following a breach announcement like this one.
Consider a Fraud Alert or Credit Freeze
If Social Security numbers or identification details were part of this breach, placing a fraud alert on your credit file is a strong precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name.
For even stronger protection, you can request a credit freeze, which restricts access to your credit file entirely. This makes it much harder for identity thieves to open new accounts using your information. Both options are free and can be requested directly through the credit bureaus.
Stay Alert to Phishing Attempts
Because attackers may use stolen information to craft convincing scam messages, it is wise to be cautious of unexpected emails, texts, or phone calls. This is especially true for messages that reference your job search or employment history.
Never click on links or provide personal information in response to unsolicited messages. Instead, contact CareerSource Palm Beach County directly using verified contact information from its official website if you want to confirm whether a message is legitimate.
Keep Records and Document Any Suspicious Activity
If you notice unusual activity connected to your identity, document it carefully. This includes saving copies of suspicious emails, noting dates of unexpected account activity, and keeping records of any calls with banks or credit bureaus.
These records can prove valuable if you need to dispute fraudulent charges or file a report with the Federal Trade Commission. In addition, thorough documentation can support a potential legal claim if you decide to consult a data breach attorney about your options.
