TechNewsReel
Live

Florida DMV Database Breached via Stolen Police Credentials

The FLHSMV confirmed that the DAVID database was compromised by the ShinyHunters cybercriminal group using a single officer's account.

TechNewsReel Newsroom · September 14, 2026

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed on September 11, 2026, that its Driver and Vehicle Information Database (DAVID) was breached. The incident underscores a systemic vulnerability in how state-level sensitive data is accessed by local law enforcement.

According to the FLHSMV, the breach was carried out by what the agency described as an "international cybercriminal organization." Security researchers and the attackers themselves have identified the group as ShinyHunters. The breach was made possible after attackers gained access to the system using compromised credentials belonging to a police department employee. Specifically, the root cause was traced back to the personal device of an officer from Plant City, which provided the entry point for the unauthorized access.

The Vulnerability of State Systems

This security failure occurred shortly after another major breach involving driver's license data, suggesting a period of heightened vulnerability for Florida's transportation records. The DAVID database is a critical repository used by law enforcement and DMV officials to track vehicle registration and driver licensing across the state. Because these systems are designed to be accessible to thousands of officers across various jurisdictions, they often rely on a wide web of distributed access points, any one of which can become a liability if not properly secured.

Industry Implications

The breach highlights a critical security flaw where high-privilege law enforcement credentials serve as a single point of failure for massive state databases. When official access is permitted on personal devices without stringent controls, the entire database is only as secure as the weakest password or the least secure smartphone in the field. For the cybersecurity industry, this incident serves as a stark reminder that the absence of mandatory multi-factor authentication (MFA) for sensitive government systems creates an unacceptable risk profile.

Remaining Questions

While the FLHSMV has confirmed the breach and the method of entry, several details remain unverified. The cybercriminal group ShinyHunters has claimed to have stolen records of over 200,000 individuals, but the state has not officially confirmed the exact volume of data exfiltrated. It remains unclear whether the state will implement new hardware-based authentication requirements for all law enforcement personnel accessing the DAVID system to prevent similar credential-based attacks in the future.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.