Florida confirms DMV database breached via stolen police account

Florida’s Driver Database Breached After Stolen Police Account Compromised

A significant security incident has shaken the state of Florida, with its Department of Highway Safety and Motor Vehicles (FLHSMV) confirming that its DAVID driver database was breached by hackers. The breach, attributed to the notorious ShinyHunters extortion gang, raises concerns about data protection and highlights the importance of robust cybersecurity measures.

According to FLHSMV, the attackers exploited a police account stored on an officer’s personal electronic device, using compromised credentials to gain unauthorized access to the database. This method contrasts with how ShinyHunters initially claimed to have breached the system – by exploiting a password reset flaw to access multiple DAVID accounts. While FLHSMV hasn’t confirmed the exact number of records accessed or stolen during the breach, the incident underscores the risks associated with weak account management and inadequate device security.

The compromised police account is believed to have been improperly stored on the officer’s personal device, raising questions about the agency’s internal security procedures. This vulnerability could have far-reaching consequences, as sensitive information related to driver records, including personal data and vehicle details, was potentially exposed. ShinyHunters claimed to have accessed over 200,000 records, although FLHSMV has not confirmed this number.

The investigation into the breach is ongoing, with FLHSMV working closely with state agencies, including the Florida Office of the Attorney General, the Florida Digital Service, and the Department of Law Enforcement. While authorities are still piecing together the details, it’s clear that this incident highlights the need for robust cybersecurity measures to protect sensitive data.

In light of this breach, one key takeaway is the importance of proper account management and device security. Employees’ personal devices should be treated as high-risk vectors, with strict policies in place for storing sensitive credentials and access information. Moreover, regular audits and assessments can help identify vulnerabilities before they’re exploited by attackers. By prioritizing cybersecurity and adopting best practices, organizations can mitigate risks and protect sensitive data from falling into the wrong hands.


Source: Bleeping Computer — 2026-09-11