Skip to content

St. Lucie County clerk website compromise causes redirects

Summary

St. Lucie County Clerk and Comptroller logo

The St. Lucie County Clerk and Comptroller’s externally hosted public website was compromised July 7, 2026, causing an hours-long homepage outage and redirecting some links to an unauthorized third-party site. Staff removed a malicious script and restored the site from a known-good backup; the clerk confirmed the compromise July 8, reported no evidence of access to internal systems or their data, and warned of possible slower performance during database re-indexing.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data alteration or manipulation

    Data was intentionally changed, falsified, manipulated, or otherwise modified without authorization.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Degraded service

    Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.

  • Intermittent service disruption

    Services or systems experienced recurring, unstable, or temporary periods of unavailability.

  • Website unavailable

    A public-facing website was unavailable, disabled, or inaccessible.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the St. Lucie County Clerk and Comptroller’s externally hosted public website was compromised July 7, 2026. DysruptionHub’s published report contained Clerk Michelle R. Miller’s July 8 confirmation that some hyperlinks redirected users to an unauthorized third-party website and that investigators identified and removed a malicious script.

The compromise was limited, based on the available evidence, to the public-facing website environment. The clerk said the website was architecturally separate from production systems and lacked backend connectivity, authentication credentials or privileged access to case-management, official-records, financial and other internal systems. Investigators found no evidence of unauthorized access to those systems or their data.

The malicious script and redirects establish unauthorized alteration of website code or content. They do not establish that production data was viewed, copied, altered or removed, or that users submitted information to the unauthorized destination.

Operational significance

WPTV reported that the office received a report shortly before 8 a.m., took the homepage offline and restored it around 1:30 p.m. The homepage is a public access point for court and official records, payments, jury services and other functions, so its unavailability and malicious redirection created a material government-service disruption and restricted normal public access.

The disruption did not make every clerk service unavailable. The office said residents could still reach information and services through direct links while the homepage was offline, providing an alternate access channel. Staff removed the script, restored the website from a known-good backup and scanned its files before returning it to service.

Disclosure posture

The office initially described the event July 7 as technical difficulties and later as a temporary redirection issue caused by a third-party service provider. Its communications team told WPTV that the event was not a hack because personal information was not compromised. Miller’s July 8 response refined that account by confirming that the externally hosted website had been compromised and that a malicious script was removed.

The distinction matters: absence of identified personal-information compromise does not mean the website was not compromised. July 7 establishes the outage and official service acknowledgement, while July 8 is the first supported organization-confirmed cyber disclosure. Miller said the initial statements reflected information available early in the investigation and that additional facts emerged as the work progressed.

Current status

The homepage returned to service July 7. On July 8, the clerk said it was operational but users could experience slower-than-normal performance while the database completed re-indexing. The exact time normal performance returned is not public.

The clerk’s website and its court-search, official-records, payment and other public-service links were operational during the July 26 review. No later incident warning, recurrence or unresolved degradation notice was found, supporting resolved status.

Confidence and uncertainty

Confidence is high in the compromise, website alteration, redirect behavior and restoration because the clerk confirmed the malicious script and remediation, and contemporaneous reporting documented the outage. Confidence is high that internal production systems and their data were architecturally separated, but medium in the broader absence-of-exposure conclusion because no public forensic report identifies the malicious destination or whether redirected users interacted with it.

The supported data impacts are alteration of website content or code and temporary unavailability of public website information. No evidence establishes internal data access, exfiltration, publication, encryption, deletion or corruption. The incident is assessed as not ransomware, no known extortion indicator was found, and threat-actor attribution remains unresolved.

Analytic gaps

The public record does not establish the initial access vector, compromised account or component, exploited vulnerability, hosting provider, persistence method, exact malicious-script behavior or duration before discovery. It also does not identify the unauthorized destination, number of redirected users, whether any user submitted information there or whether other hosting customers were affected.

No later technical report establishes precisely when database re-indexing ended or whether the office made additional nonpublic notifications under Florida cybersecurity reporting requirements. A later provider advisory, forensic report, user-harm report or regulatory filing could materially change the assessment.

Organizations involved

Impacted locations

Sources

St. Lucie County, Florida, clerk says public website was compromised

Clerk Michelle R. Miller confirmed July 8 that the externally hosted public website had been compromised, some hyperlinks redirected users to an unauthorized third-party site and a malicious script was removed. The site was restored from a known-good backup; investigators found no evidence of access to internal systems or their data, while temporary slower performance could continue during database re-indexing.

St. Lucie County Clerk and Comptroller

The St. Lucie County Clerk and Comptroller website was operational during the July 26 review, with court case search, official-records search, payment, jury, marriage, forms and other public-service links available. No current incident warning or performance-degradation notice was displayed.

St. Lucie County Clerk and Comptroller Facebook notice

The clerk’s office publicly said it was experiencing website technical difficulties and was working to restore service; a later statement described a temporary redirection issue and said no personal or confidential information was compromised or at risk.

Why did the St. Lucie County Clerk's office website go down for hours?

WPTV reported that the clerk’s office received a report shortly before 8 a.m. July 7, took the affected homepage offline and restored it by about 1:30 p.m. The office said direct links to records, payments and other services remained usable, described the problem as a third-party redirection issue and reported no compromise of personal information.

See something that needs correction?

Signed-in members can report an error, update, or missing source.