Skip to content
Tech News
← Back to articles

Florida confirms DMV database breached via stolen police account

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

A single set of police credentials stored on a personal device was enough to expose Florida's DAVID driver database, which holds highly sensitive personal and vehicle records for millions of residents. The incident shows how law enforcement data-sharing systems are only as secure as their least careful authorized user, and it raises questions about oversight of who can query these databases. Florida's account of the intrusion also conflicts with the attackers' claim of a password reset flaw, leaving the true scope unresolved.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — This breach traces back to login credentials stashed on a personal device "" exactly the weak point a hardware security key eliminates. The YubiKey 5 NFC plugs into USB-A or taps an NFC phone to approve logins, so an account can't be taken over with a stolen password alone. It's a pocket-sized upgrade for email, cloud, and password manager accounts.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach after the ShinyHunters extortion gang claimed to have compromised the system.

The disclosure comes after the ShinyHunters extortion group claimed it breached the DAVID database and stole more than 200,000 driver records.

"On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization," the agency said in a statement posted to X.

"The data breach was quickly mitigated and no further breach has occurred or is ongoing."

FLHSMV says its investigation determined that the attacker used compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee's personal electronic device.

The agency says it has notified the Florida Office of the Attorney General of the breach and is working with the Florida Digital Service and Florida Department of Law Enforcement as part of its response.

"As this is an ongoing criminal investigation, further information will be released at an appropriate time in the future," FLHSMV said.

ShinyHunters claimed a different access method

FLHSMV's findings are different from how ShinyHunters previously claimed to have gained access to the database.

The hackers claimed they exploited a password reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and an FBI agent.

... continue reading