top of page
OutSystems-business-transformation-with-gen-ai-ad-300x600.jpg
OutSystems-business-transformation-with-gen-ai-ad-728x90.jpg
TechNewsHub_Strip_v1.jpg

LATEST NEWS

Florida confirms DMV database breach via stolen police credentials

Marijan Hassan - Tech Journalist
1 hour ago
2 min read

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed a data breach affecting its Driver and Vehicle Information Database (DAVID) after an international cybercrime group gained unauthorized access using stolen law enforcement credentials. The disclosure follows claims by the extortion group ShinyHunters, which boasted on its dark web leak site that it had exfiltrated more than 200,000 driver records.


Editorial credit: Bilanol / Shutterstock
Editorial credit: Bilanol / Shutterstock

While state officials confirmed the incident, they stated the intrusion was rapidly contained and rejected claims of an ongoing system compromise.


Initial Access Vector Traced to Police Officer's Device

An internal investigation conducted by the state alongside the Florida Digital Service and the Florida Department of Law Enforcement revealed that the threat actors did not exploit a perimeter vulnerability in the DMV's core infrastructure. Instead, the attackers harvested valid login credentials belonging to a single Plant City Police Department employee.


The credentials were improperly stored on the officer's personal electronic device, allowing the threat actors to authenticate to the DAVID system and query law enforcement databases legitimately.


Discrepancy in Breach Claims

ShinyHunters originally claimed it leveraged a password-reset vulnerability across multiple DMV and FBI user accounts to iterate through record IDs. FLHSMV disputed this mechanism, attributing the incident solely to the compromised police account.


Exfiltrated Record Samples

To corroborate its claims, ShinyHunters posted sample screenshots of sensitive files pulled from DAVID, including driver photos, signatures, Social Security numbers, residential addresses, and vehicle registration histories.


Mitigation and Containment

FLHSMV confirmed that access via the compromised account was revoked shortly after detection on September 4, and the incident was reported to the Florida Office of the Attorney General.


Broader Risks to Law Enforcement Portals

The DAVID database serves as a centralized state repository, granting law enforcement agencies and criminal justice personnel real-time access to motorist profiles, traffic histories, and vehicle registration data.


Cybersecurity analysts emphasize that the incident underscores systemic risks in law enforcement trust networks. When external agencies are granted portal access, poor endpoint security or unmanaged personal devices can compromise state-level databases regardless of internal DMV security controls. The investigation remains active, with state and federal authorities monitoring potential extortion attempts and dark web leaks tied to the stolen data.

wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page