Ransomware victim disclosure
← All victimsState of Florida
Claimed by Clop · listed 2 hours ago
Status timeline
- ListedSep 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Sector
- Government
- Listed on leak site
- Sep 20, 2026
- Data size
- 541 GB
- Records
- Hundreds of millions of records/rows
About the victim
AI dossier — public-source company profileThe State of Florida is a U.S. state government entity responsible for administering public services and operations across the state. The victim designation refers to Florida state government infrastructure and data systems.
- Industry
- Government Administration
Attack summary
Severity: critical — Confirmed exfiltration of 541 GB of government data at massive scale including PII (employee and customer), sensitive operational security documentation (data center schematics, access controls, credentials), critical infrastructure blueprints, and security policies. Exposure of credential artifacts and access-control lists poses immediate operational and security risk to state government systems.Clop claims to have exfiltrated 541 GB of data from Florida state government systems, including Salesforce records (12.9 million records claimed), SharePoint files, employee PII, customer data, physical security documentation, data center schematics, credentials, and access-control artifacts. The group claims to have encrypted systems and published data after failed ransom negotiations.
Data the group says was taken
AI dossier — extracted from the leak post- 12.9 million Salesforce records
- 645 GB SharePoint data (uncompressed)
- Customer contact data (182,000+ rows)
- Employee PII (8,300+ rows: names, emails, job titles, phone numbers)
- Executed contracts, MSAs, NDAs, leases, SOWs
- Physical key inventory logs and verification photos
- Data center drawings, floor plans, electrical diagrams, security schematics
- CERM process library
- Physical and information security policies
- Security scorecards and KPI workbooks
- Credential and access-control artifacts (PasswordList.xlsx, Okta SSC access lists, badge reports, data center access control forms)
What the group claims
State of Florida failed to reach an agreement despite multiple chances and offers. Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI.
The leak post
captured from the group's site**IF YOU WANT TO SAVE YOUR BRAND AND NOT DIE BY MY HANDS:** Email us from your official email at [email protected] and lets see how rich you really are. 2.333% of my networth is a 8 figure amount, I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism. We are aware of the situation involving a number of our CDNs being unreachable. We are working on restoring them. We estimate 24 to 48 hours till they are back. 91.215.85.22 remains accessible and usable. **Update, July 27, 3:01 a.m. ET:** All CDN mirrors are back online; however, content synchronization across all three mirrors is still ongoing. Addicionally, we are still working on preparing the release of the torrents. We kindly ask our visitors to seed once they become available. A notification will be posted upon release. All CDN mirrors are currently experiencing a service disruption. **All files are fully backed up and no data has been lost.** At this time we do not have an estimated time of resolution.We are working to restore service promptly and will share updates as they become avail…
Data the group says was taken
- PII
- PHI
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

