TechNewsReel
Live

Florida DMV Database Breached via Stolen Police Credentials

A security failure involving a personal device allowed attackers to access the state's sensitive driver and vehicle information system.

TechNewsReel Newsroom · September 12, 2026

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed on September 11, 2026, that its driver and vehicle database was compromised. The breach underscores a critical vulnerability in how law enforcement credentials are managed and stored.

According to FLHSMV, attackers gained unauthorized access to the DAVID (Driver and Vehicle Information Database) system. The entry point was traced back to stolen login credentials belonging to a single employee of the Plant City Police Department. Investigators found that these credentials had been stored on a personal electronic device that was not issued or managed by the state agency. The cybercrime group known as ShinyHunters has since claimed responsibility for the attack.

The Vulnerability of DAVID

The DAVID system serves as one of Florida's most sensitive law-enforcement tools, providing officers and authorized personnel with real-time access to driver's license and vehicle registration data. Because the system is designed for rapid access across various jurisdictions, it relies on a network of credentials distributed to numerous police departments across the state. In this instance, the failure to adhere to secure credential storage protocols transformed a single officer's personal device into a gateway for external attackers.

Industry Implications

This incident highlights a systemic risk associated with the "shadow IT" practice of using personal devices to access government databases. When administrative credentials move outside of managed corporate or government environments, they bypass the security controls—such as remote wiping and mandatory encryption—that agencies rely on to prevent data theft. The breach demonstrates that the security of a massive state database is only as strong as the least secure device used to access it.

Next Steps

While the breach has been confirmed, the full scope of the data exfiltration remains unclear. State officials have not officially verified the total number of records stolen, despite claims from the attackers. Observers are now watching for whether FLHSMV will implement stricter multi-factor authentication (MFA) requirements or mandate that DAVID access be restricted exclusively to government-managed hardware to prevent similar credential leaks in the future.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.