Florida’s Driver Database Breached by Stolen Police Account Credentials
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database was compromised in a data breach, with over 200,000 driver records stolen. The incident highlights the importance of robust cybersecurity measures, particularly when it comes to sensitive government databases.
According to FLHSMV’s statement, the breach occurred after an attacker used stolen credentials from a Plant City Police Department user who had improperly stored them on their personal electronic device. This compromised account was then used to gain access to the DAVID database. The agency has notified the Florida Office of the Attorney General and is working with law enforcement agencies as part of its response.
The breach has sparked an investigation, which has revealed that the attacker did not exploit a password reset flaw, as claimed by the ShinyHunters extortion gang. Instead, it appears that the compromised account was used to gain unauthorized access to the database. This discrepancy raises questions about how the attackers initially gained control of the account and whether there were any weaknesses in FLHSMV’s security measures.
The breach has significant implications for those whose data may have been compromised. The DAVID database contains sensitive information, including personal details and vehicle records. While FLHSMV has not disclosed how many records were accessed or stolen during the breach, it is likely that the affected individuals will be notified in due course.
This incident highlights the importance of robust cybersecurity measures for government agencies and other organizations that handle sensitive data. It also underscores the need for employees to follow best practices when handling credentials, such as storing them securely and using strong passwords. By taking these steps, organizations can reduce the risk of data breaches and protect their stakeholders’ sensitive information.
As the investigation into this breach continues, FLHSMV has promised to release further information in due course. In the meantime, it is essential for individuals to remain vigilant and monitor their credit reports for any suspicious activity. By taking proactive steps to protect their personal data, they can minimize the risk of identity theft and other malicious activities.
This incident serves as a stark reminder that even with robust security measures in place, data breaches can still occur due to human error or compromised credentials. To mitigate this risk, organizations must prioritize cybersecurity awareness and education for their employees, ensuring that everyone understands the importance of secure password management and data handling practices.
Source: Bleeping Computer — 2026-09-11