Florida DMV Confirms Breach via Stolen Police Credentials

Florida authorities say a hacker group accessed the state's driver database using a single compromised police account, contradicting the attackers' claim of a systemic flaw.
The Florida Department of Highway Safety and Motor Vehicles has confirmed that its central driver database was breached. The agency stated that the intrusion occurred on September 4, 2026, when an international cybercriminal organization gained unauthorized access to the system. This disclosure follows recent claims by the extortion group ShinyHunters, which alleged it had stolen over 200,000 driver records.
According to the department, the breach was quickly contained, and no further unauthorized access is currently ongoing. The investigation revealed that the attacker did not exploit a software vulnerability in the database itself. Instead, the intrusion was facilitated by compromised login credentials belonging to a single employee of the Plant City Police Department.
Stored credentials enabled the intrusion
The root cause of the breach appears to be a failure in basic credential management. The Florida department determined that the police employee had improperly stored their login details on a personal electronic device. This practice allowed the attackers to obtain valid access to the state's DAVID database, which holds sensitive information on drivers and vehicles.
This incident highlights a significant security trade-off in how agencies handle shared or delegated access. While using personal devices for work tasks offers convenience, it creates a fragile point of entry that can bypass robust server-side security measures. The department has notified the Florida Office of the Attorney General and is collaborating with the Florida Digital Service and the Department of Law Enforcement to manage the response.
Hackers claimed a different method
There is a discrepancy between the official findings and the claims made by ShinyHunters. The hacking group previously asserted that they exploited a password reset flaw to access multiple accounts, including those of DMV employees and an FBI agent. They claimed to have systematically downloaded records and shared a screenshot of a sensitive file as proof.
However, the state agency has not confirmed the scale of the data theft or the specific technical vector used. BleepingComputer reported that ShinyHunters later stated they lost access to the system, suggesting the alleged flaw may have been patched. The official narrative remains that the breach was a result of stolen credentials rather than a systemic exploit.
Uncertainty remains over data scope
The primary catch for affected individuals is the lack of clarity regarding exactly what was taken. The Florida department has not disclosed how many records were accessed or stolen. It has also not validated the hackers' claim that more than 200,000 files were compromised. Until the criminal investigation concludes, residents will have to wait for further details on the extent of the exposure.
As the investigation continues, the department has indicated that further information will be released at an appropriate time. For now, the confirmed fact is that a single point of failure in credential storage exposed the state's driver data, a reminder that human error often remains the weakest link in digital security infrastructure.






