Clearwater Public Library System

A Pinellas County arrest affidavit alleges that a former Clearwater Public Library System technology employee used a library administrative account on February 5, 2026, to remove Deep Freeze security software from about 200 public computers. The action led the city to shut down patron computers at three Florida library branches, while the accused employee pleaded not guilty and no theft, fraud or misuse of personal information was alleged.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malicious or negligent actions by an authorized insider resulting in cyber impact.
Unauthorized access to systems, accounts, networks, or data.
Available evidence indicates that the incident did not materially affect the confidentiality, integrity, or availability of data.
A primary service, system, platform, or operational capability became entirely unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that malicious use of a city library administrative account caused a documented public-computer disruption in Clearwater, Florida. A sworn Pinellas County complaint and arrest affidavit alleges that a former Clearwater library technology employee used the account on February 5 to remove Deep Freeze security software from approximately 200 computers operated for the city. The filing says audit logs tied the action to the account’s multi-factor authentication and to a login from an IP address in Oldsmar.
The public record supports an insider-threat and unauthorized-access characterization, but responsibility remains a criminal allegation rather than a final adjudication. The named former employee pleaded not guilty. DysruptionHub therefore distinguishes high confidence that malicious account activity and service disruption occurred from unresolved confidence in the ultimate attribution to the charged individual.
Removing the security software left the affected computers unsecured and susceptible to malware or viruses, according to the affidavit. The city shut down and took the systems offline, interrupting public computer access at the Main, Countryside and North Greenwood libraries. The library system’s public notice directed patrons to the East Community Library or partner libraries for computer access.
Public computers are a material library service for residents who rely on them for internet access, documents, applications and other digital tasks. The disruption did not close the three branches or establish an outage of the catalog, Wi-Fi, circulation, website or other library functions, so its documented scope is the patron-computer service rather than the entire library system.
The library publicly acknowledged the computer outage on February 10 without identifying a cyber cause. The earliest identified public cyber evidence appeared March 4, when the affidavit was filed and local reporting described investigators’ allegations. DysruptionHub’s published report later added direct confirmation from Clearwater police about the affected branches, the former employee’s role and the pending case.
The later felony charge explains the disruption as alleged intentional insider-linked activity rather than ransomware or an unexplained technology failure. That later evidence strengthens the cyber assessment but does not convert the allegation against the defendant into a final finding of guilt. His defense attorney said there were no allegations of theft, fraud or misuse of personal information.
The last identified incident-specific operational notice was the February 10 statement that the affected public computers were unavailable. The library’s current computer-services information again describes public computers as available at its branches, providing a recovery signal, but no located incident-specific notice states when every affected computer returned to service. DysruptionHub therefore assesses the operational impact as presumed resolved rather than assigning a confirmed restoration date.
Confidence is high that the administrative account was used to remove Deep Freeze and that public computers were taken offline, based on the sworn affidavit, audit-log description and official library outage notice. Confidence is high that the incident was not ransomware because the documented mechanism was security-software removal and the public record identifies no encryption or ransom activity.
Data theft or misuse is not established. The defense said no such conduct was alleged, and the reviewed public sources do not identify unauthorized access to patron records, credentials, browsing activity or other personal information. They also do not establish whether any data was deleted, altered or exposed while the systems were unsecured.
The public record does not establish the defendant’s alleged motive, whether the administrative account remained authorized at the time of access, the full permissions and systems reachable through that account, the precise restoration process, the duration of each branch’s outage, or whether the city found malware or additional unauthorized activity. The final criminal disposition, any independent forensic findings and the exact date of full computer-service restoration remain unresolved.

All three affected library branches are within Clearwater, Florida.
DysruptionHub reported that the affidavit alleges a former library technology employee used library credentials to remove Deep Freeze from about 200 public computers. Clearwater police identified the Main, Countryside and North Greenwood branches as affected, while the defense said the accused pleaded not guilty and no theft, fraud or misuse of personal information was alleged.
The Clearwater Public Library System said all public computers at the Countryside, Main and North Greenwood libraries were out of service and directed patrons to the East Community Library or Pinellas Public Library Cooperative partner locations for computer access.
The sworn affidavit alleges that a former employee willingly and knowingly disrupted city computer services, used a Clearwater library administrative account and associated MFA, and removed Deep Freeze from about 200 computers. It says the city shut down the computers after the removal left them unsecured and susceptible to malware or viruses.
IONTB reported from the complaint and arrest affidavit that investigators accused a former city employee of removing Deep Freeze from about 200 library computers through an administrative account tied to his MFA and an Oldsmar IP address. The systems were shut down and taken offline, interrupting government operations and public services.
The library system’s current FAQ describes public computers as available at its branches, providing a present-day recovery signal without stating when the February 2026 incident was fully resolved.
The City of Clearwater’s official website identifies the Clearwater Public Library System as a five-branch municipal library system and lists the Main, Countryside, North Greenwood, East Community and Beach locations.
Official profile information supporting the public description of Clearwater Public Library System.
Signed-in members can report an error, update, or missing source.