Skip to content
Back to Blog
high severity November 13, 2023 · 4 min read Unverified claim — what this is

St. Lucie County Tax Collector’s Listed by alphv Ransomware Group

If you are a resident of St. Lucie County Tax Collector’s, here’s what is being claimed, and what it would mean for you.

Proof of Leakage First part listing Full data dump soon... - more personal data with SSN, address, DOB, DL, W4, W9, CC

— from Alphv’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
St. Lucie County Tax Collector’s Listed by alphv Ransomware Group

On November 13, 2023, the St. Lucie County Tax Collector’s office in Florida appeared on the leak site operated by the alphv ransomware group. The listing states that internal files were exfiltrated during a ransomware attack, with a partial sample already published and a full data dump promised soon. The sample and description indicate the presence of highly sensitive personal information including SSNs, addresses, dates of birth, driver’s licenses, W-4 forms, W-9 forms, and credit card details.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Details from the Leak-Site Listing

The alphv leak page for this incident explicitly notes “Proof of Leakage First part listing” followed by the warning “Full data dump soon.” It describes the stolen material as containing more personal data with SSN, address, DOB, DL, W4, W9, and CC. The disclosure does not quantify the number of affected individuals, nor does it specify the exact volume of records or the precise systems that were initially compromised. What is confirmed is that the county tax collector’s internal files were taken and are now held by the extortion actors.

November 13, 2023 marks the first public listing of this claimed breach on the alphv portal. The notification style is typical of modern ransomware operations: a partial leak to prove access, followed by the threat of wholesale publication unless payment is made.

Why This Matters for You and Your Family

If you or any member of your household has lived in St. Lucie County, worked there, or conducted business with the Tax Collector’s office, your personal information may now sit on a criminal server. Tax offices routinely handle driver’s license renewals, property records, tax filings, and payment information. A breach of this type therefore exposes the exact details criminals need to file fraudulent tax returns, open accounts in your name, or impersonate you with government agencies.

SSNs, driver’s licenses, dates of birth, and credit card numbers together create immediate financial and identity-theft risk. Even if the full dump has not yet been released, the partial files already published give threat actors enough to begin targeted attacks against residents and employees alike.

The Doxxing and Identity-Chain Implications

Once SSNs, addresses, and dates of birth leave official custody, they rarely stay isolated. Criminals combine them with usernames, emails, or phone numbers obtained from other breaches to build detailed profiles. These identity chains can link your government records to social-media handles, gaming accounts, and family members’ information. Children’s records are especially vulnerable because parents often reuse credentials across tax portals, email, and online gaming services.

A single leak like this can cascade into account takeovers that expose chat logs, friend lists, and location data, accelerating doxxing campaigns. Public reporting on similar incidents shows that ransomware groups frequently sell or auction such datasets on underground forums, where buyers specifically hunt for combinations of government identifiers and personal contact details.

Alphv’s Publicly Known Track Record

Public reporting attributes the alphv ransomware group, also known as BlackCat, with emerging in late 2021. The gang has since claimed responsibility for attacks against hundreds of organizations across healthcare, education, local government, and critical infrastructure sectors. Notable prior victims include large healthcare providers, municipal governments, and technology companies. Their typical playbook involves initial access through phishing or exploited remote desktop services, followed by rapid exfiltration of sensitive files before encryption. They then publish samples on their leak site and demand payment within a short window, often threatening to release the full archive or sell it to third parties if unpaid.

What to do

  • Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity drawn from this and prior exposures.
  • Rotate any password you have used with the St. Lucie County Tax Collector’s online systems and enable 2FA through an authenticator app rather than SMS.
  • Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next leak exposing you is caught in hours, not months.
  • Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts, which often chain back to the same address and parent credentials.
  • Let remediation specialists handle takedown requests and broker removal on your behalf while you focus on securing accounts and freezing credit reports.

The incident underscores how quickly local-government data can fuel broader identity crimes when it lands in the hands of professional ransomware operators. Acting promptly on the credentials and personal details already at risk can limit the damage before the promised full dump appears. DoxxScan’s continuous monitoring, AI-powered identity-chain mapping, hands-on remediation by specialists, and household coverage provide a practical way for you and your family to track and reduce these cascading exposures, including those that threaten children’s gaming accounts.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
St. Lucie County Tax Collector’s is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed November 13, 2023
Last reviewed August 8, 2026
Affected Unconfirmed
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email