St. Lucie County Clerk and Comptroller

The St. Lucie County Clerk and Comptroller’s externally hosted public website was compromised July 7, 2026, causing an hours-long homepage outage and redirecting some links to an unauthorized third-party site. Staff removed a malicious script and restored the site from a known-good backup; the clerk confirmed the compromise July 8, reported no evidence of access to internal systems or their data, and warned of possible slower performance during database re-indexing.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized modification or replacement of website content.
Data was intentionally changed, falsified, manipulated, or otherwise modified without authorization.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.
Services or systems experienced recurring, unstable, or temporary periods of unavailability.
A public-facing website was unavailable, disabled, or inaccessible.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that the St. Lucie County Clerk and Comptroller’s externally hosted public website was compromised July 7, 2026. DysruptionHub’s published report contained Clerk Michelle R. Miller’s July 8 confirmation that some hyperlinks redirected users to an unauthorized third-party website and that investigators identified and removed a malicious script.
The compromise was limited, based on the available evidence, to the public-facing website environment. The clerk said the website was architecturally separate from production systems and lacked backend connectivity, authentication credentials or privileged access to case-management, official-records, financial and other internal systems. Investigators found no evidence of unauthorized access to those systems or their data.
The malicious script and redirects establish unauthorized alteration of website code or content. They do not establish that production data was viewed, copied, altered or removed, or that users submitted information to the unauthorized destination.
WPTV reported that the office received a report shortly before 8 a.m., took the homepage offline and restored it around 1:30 p.m. The homepage is a public access point for court and official records, payments, jury services and other functions, so its unavailability and malicious redirection created a material government-service disruption and restricted normal public access.
The disruption did not make every clerk service unavailable. The office said residents could still reach information and services through direct links while the homepage was offline, providing an alternate access channel. Staff removed the script, restored the website from a known-good backup and scanned its files before returning it to service.
The office initially described the event July 7 as technical difficulties and later as a temporary redirection issue caused by a third-party service provider. Its communications team told WPTV that the event was not a hack because personal information was not compromised. Miller’s July 8 response refined that account by confirming that the externally hosted website had been compromised and that a malicious script was removed.
The distinction matters: absence of identified personal-information compromise does not mean the website was not compromised. July 7 establishes the outage and official service acknowledgement, while July 8 is the first supported organization-confirmed cyber disclosure. Miller said the initial statements reflected information available early in the investigation and that additional facts emerged as the work progressed.
The homepage returned to service July 7. On July 8, the clerk said it was operational but users could experience slower-than-normal performance while the database completed re-indexing. The exact time normal performance returned is not public.
The clerk’s website and its court-search, official-records, payment and other public-service links were operational during the July 26 review. No later incident warning, recurrence or unresolved degradation notice was found, supporting resolved status.
Confidence is high in the compromise, website alteration, redirect behavior and restoration because the clerk confirmed the malicious script and remediation, and contemporaneous reporting documented the outage. Confidence is high that internal production systems and their data were architecturally separated, but medium in the broader absence-of-exposure conclusion because no public forensic report identifies the malicious destination or whether redirected users interacted with it.
The supported data impacts are alteration of website content or code and temporary unavailability of public website information. No evidence establishes internal data access, exfiltration, publication, encryption, deletion or corruption. The incident is assessed as not ransomware, no known extortion indicator was found, and threat-actor attribution remains unresolved.
The public record does not establish the initial access vector, compromised account or component, exploited vulnerability, hosting provider, persistence method, exact malicious-script behavior or duration before discovery. It also does not identify the unauthorized destination, number of redirected users, whether any user submitted information there or whether other hosting customers were affected.
No later technical report establishes precisely when database re-indexing ended or whether the office made additional nonpublic notifications under Florida cybersecurity reporting requirements. A later provider advisory, forensic report, user-harm report or regulatory filing could materially change the assessment.

Clerk Michelle R. Miller confirmed July 8 that the externally hosted public website had been compromised, some hyperlinks redirected users to an unauthorized third-party site and a malicious script was removed. The site was restored from a known-good backup; investigators found no evidence of access to internal systems or their data, while temporary slower performance could continue during database re-indexing.
The St. Lucie County Clerk and Comptroller website was operational during the July 26 review, with court case search, official-records search, payment, jury, marriage, forms and other public-service links available. No current incident warning or performance-degradation notice was displayed.
The clerk’s office publicly said it was experiencing website technical difficulties and was working to restore service; a later statement described a temporary redirection issue and said no personal or confidential information was compromised or at risk.
WPTV reported that the clerk’s office received a report shortly before 8 a.m. July 7, took the affected homepage offline and restored it by about 1:30 p.m. The office said direct links to records, payments and other services remained usable, described the problem as a third-party redirection issue and reported no compromise of personal information.
Signed-in members can report an error, update, or missing source.