Data breach
Florida East Coast Railway
- Records
- 16,668
- Breach date
- 7 May 2026Estimated
- Added
- 20 May 2026
What was exposed
9 types of data · 2 put you at serious risk
- Names16,668
- Email addresses8,791
- Phone numbers7,481
- Social security numbers2,888
- Street addresses1,889
- Dates of birth1,501
- Driving licence numbers304
- Licence plates200
- Vehicle VINs155
About this breach
Florida East Coast Railway, a freight railroad that runs roughly 351 miles of track from Jacksonville to Miami, appears in a new data breach listing. According to our investigation team, a dataset tied to the company surfaced on May 20, 2026, containing 16,668 rows of records. Our team estimates the breach occurred on or around May 7, 2026. The listing has not been claimed by any actor in our index, and the company itself has not publicly confirmed the breach.
The incident has, however, drawn outside attention. Ransomware.live, a site that tracks extortion claims, lists Florida East Coast Railway as a victim of the group calling itself PayoutsKing, with a listing first discovered on April 30, 2026. The group threatened to release stolen data unless the company entered negotiations. Independent trackers note that this remains an unconfirmed extortion claim, with no regulator filing, breach index entry, or named news outlet corroborating it beyond the group's own posting.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: full names across all 16,668 records, along with 8,791 email addresses, 7,481 phone numbers, 2,888 Social Security numbers, 1,889 street addresses, 1,501 dates of birth, 304 driver's license numbers, 200 vehicle license plates, and 155 vehicle identification numbers.
Not every individual is affected by every type of data listed here.
The presence of Social Security numbers and driver's license numbers is the most serious element of this listing. Contact details such as names, emails, and phone numbers are widespread in the dataset, while the identity documents and vehicle records appear in smaller subsets.
What Are the Potential Risks for Affected Individuals?
Anyone whose Social Security number or driver's license number was exposed faces a real risk of identity theft. Criminals can use those records to open bank accounts, apply for loans or credit cards, file fraudulent tax returns, or impersonate victims with government agencies.
The combination of names, birthdates, addresses, and phone numbers also enables highly convincing phishing. A message that knows your full name, birthdate, and address feels legitimate in a way generic spam does not. Recipients should treat unexpected calls, texts, and emails with suspicion, even when the sender appears to know personal details.
Because this breach has not been officially confirmed by the company, it is possible that some or all of the indexed data is incomplete or inaccurate. That uncertainty does not eliminate the risk, but it should temper assumptions about what happened.
What Should You Do If You Were Affected?
Check whether your email address appears in this breach using the search tool.
Place a free fraud alert or a credit freeze with the three major credit bureaus, Equifax, Experian, and TransUnion. A freeze blocks most new credit from being opened in your name.
Review your credit reports for accounts you do not recognize. You can pull free reports from each bureau.
If you file taxes, consider obtaining an Identity Protection PIN from the IRS to prevent fraudulent return filings.
Watch for phishing attempts that reference your personal details. Do not click links in unexpected messages, and verify requests for money or information through a separate channel.
Change passwords on important accounts and enable two-factor authentication where it is offered.
Monitor explanations of benefits and insurance claims for services you did not receive.
Because no company notice has been published, there is currently no official notification letter or dedicated support channel for this incident as of September 25, 2026. Affected individuals should rely on the protective steps above rather than waiting for one.
