The Family Partnerships of Central Florida 2025 data breach involved unauthorized access to systems operated by the child and family services organization, also known as Community Based Care Brevard, from December 4, 2025, through January 2, 2026. The organization officially confirmed that certain files connected to the incident were copied and removed from its systems.
The affected files could contain names, dates of birth, Social security numbers, driver's-license or state-identification numbers, financial-account information, and personal health information. Public state figures identify 89 Massachusetts residents and two Vermont residents; those figures establish a verifiable lower bound of 91 people, not a nationwide total.
How Was the Family Partnerships Breach Confirmed?
The strongest primary source is the organization's “Notice of Data Event” document published on fpocf.org. It directly describes the unauthorized-access dates, copying and removal of information, investigation, affected information categories, security response, and dedicated assistance line. The organization's own notice moves the event beyond an allegation and provides the core evidence.
A July 17, 2026, recipient letter in the Massachusetts Attorney General archive supports the entity identity, notification process, statement about misuse, and 24-month protection offer. Claim Depot connects the official documents to the same event and summarizes the population figures reported for Massachusetts and Vermont. The three sources align on the material facts.
What Happened From December 4 Through January 2?
Family Partnerships said it was alerted that data belonging to the organization had been leaked online by an unauthorized third party. An investigation with outside forensic specialists found that an unauthorized actor accessed certain systems between December 4, 2025, and January 2, 2026, and copied or removed information stored there. The organization then reviewed documents to identify people and data types.
The sources do not say whether initial access resulted from phishing, a stolen password, an exposed service, or a software vulnerability. Claim Depot reports that a group called Money Message claimed responsibility on January 28, but the organization's primary notice does not validate that actor. The claim is therefore not recorded as official attribution or as the incident's technical root cause.
What Personal and Health Information Was Affected?
The exact list in the official organization notice is name, date of birth, Social Security number, driver's-license or state-identification number, financial-account information, and personal health information. The notice says these categories appeared in affected files; it does not say every recipient had every category. The field list in an individual's own letter is more specific for that person.
The sources do not separately identify addresses, email addresses, passwords, card CVVs, bank PINs, medical diagnoses, prescriptions, laboratory results, or insurance member numbers as confirmed fields. “Financial account information” and “personal health information” are broad categories, and expanding them into undocumented subfields would distort the risk. LeakData lists only published categories.
How Many People Were Affected?
The public state-notification figures reported for this incident are 89 people in Massachusetts and two in Vermont. The combined 91 represents only substantiated records from those two states, so it is stored as a lower bound. The organization is based in Florida and has not published a deduplicated nationwide victim total; treating two state counts as the event's exact total would be misleading.
The number of children, families, employees, or partners served by the organization cannot substitute for a victim count. An actor's claimed data volume also cannot be converted into unique people. Accordingly, pwnCount and totalRecords remain null, while 91 is stored in affectedCountLowerBound and labeled “at least.” LeakData imported no raw person records from the incident.
How Did the Organization Respond?
Family Partnerships said it secured its computer environment after learning of the incident, investigated the activity with outside specialists, and reviewed the affected files. It also said it was reviewing policies, procedures, and processes governing the storage of and access to sensitive information. At notice time, it reported no indication of actual or attempted misuse of the affected information.
The Massachusetts recipient letter says eligible individuals were offered 24 months of complimentary single-bureau credit monitoring, a credit report, a credit score, and fraud assistance through Cyberscout. Enrollment requires the letter's unique code within 90 days of the letter date. The assistance line at 1-855-302-7461 operates weekdays from 8 a.m. to 8 p.m. Eastern Time, excluding U.S. holidays.
What Should Affected People Do?
A recipient should first confirm the fields identified in the personal notice. If an SSN or government ID was affected, consider free freezes at all three credit bureaus, a fraud alert, and an IRS IP PIN. For financial-account information, review transactions and unfamiliar payment instructions; for health information, inspect benefit statements, provider records, and unexplained services.
The child and family services context may help criminals craft targeted calls or messages about document updates, benefits, or assistance payments. Open fpocf.org and the official channel in the notice independently rather than following an inbound link. Do not give a caller a password, full SSN, bank verification code, or one-time code merely because the caller knows a real name, service relationship, or affected field.