CareerSource Palm Beach County Data Breach

Alleged

Ransomware claim involving CareerSource Palm Beach County

Published: Sep 1, 2026 TheGentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
CareerSource Palm Beach County
Industry
Government
Threat Actor
TheGentlemen
Date of Incident
Sep 1, 2026

Executive Summary

TheGentlemen ransomware group listed CareerSource Palm Beach County on September 1, 2026. This listing was flagged by SOCRadar Dark Web Monitoring. CareerSource Palm Beach County serves as Florida’s regional workforce development board for Palm Beach County, responsible for administering employment services, job training programs, and economic assistance. As a public agency managing sensitive personal and employment data for a large population, it represents a high-value target for ransomware actors. TheGentlemen has been identified as a prolific ransomware group, claiming 253 other victims in the preceding 60 days. Their primary targets include the Manufacturing, Technology, and Other sectors, with a consistent focus on U.S.-based professional and government-adjacent services. Geographically, their activity is concentrated in the United States, United Kingdom, and Germany. Other U.S. Professional Services organizations previously targeted by TheGentlemen include Glassdoor, Gould Sherwood Consulting, Halliday Watkins Mann, and Saudi Consulting Services SAUD CONSULT, indicating a pattern of targeting entities within this sector.

Technical Analysis

A query into stealer-log data for the domain careersourcepbc[.]com revealed significant findings, with 11 records spanning from July 2025 through August 2026. All these records are associated with a single corporate email address, indicating a potential persistent compromise involving a single identity. The observed endpoints include Microsoft Entra (formerly Azure AD), the Duo MFA portal, and Salesforce, which is utilized for customer and grants management. The presence of credentials for a single identity across Microsoft 365, a Duo MFA endpoint, and Salesforce for over 13 months constitutes a high-severity finding, indicative of a pre-ransomware access pattern with a long dwell time. The exposure related to the Duo MFA portal is particularly concerning, as a compromise of Multi-Factor Authentication can fundamentally undermine security controls, potentially leaving the identity infrastructure unprotected even when appearing to be MFA-enforced. This situation represents a critical pre-ransomware access pattern characterized by a single compromised identity with extended dwell time and broad access across critical services. Immediate actions should include credential rotation and a mandatory MFA re-enrollment for the affected identity. Furthermore, a thorough review of Microsoft Entra sign-in logs and Salesforce access history for any anomalous activities occurring from July 2025 onwards is recommended to identify the full scope of the potential intrusion.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.