Florida's Driver Database Fell to One Stolen Police Login

Florida's answer to how its driver database got breached should read like a scene from a security audit gone wrong. The Florida Highway Safety and Motor Vehicles agency confirmed this week that DAVID — the Driver and Vehicle Information Database that law enforcement uses to look up pretty much anyone on the road in the state — was compromised by an "international cybercriminal organization," and the entry point was a single set of credentials: one Plant City Police Department employee's login, which had been "improperly stored on the employee's personal electronic device." That's the whole vector. No zero-day, no third-party vendor, no exotic exploit chain — just one account that opened the entire building. ShinyHunters, the extortion group claiming the breach, says it took more than 200,000 driver records and posted Jeffrey Epstein's DMV record as proof: address, Social Security number, date of birth, license number, and registered vehicles. FLHSMV says the breach was "quickly mitigated" and nothing is ongoing, but the criminal investigation is still open, and the deadline ShinyHunters set for publishing the files has already come and gone.

What makes this worse than a run-of-the-mill breach is what sits inside DAVID. It's not a marketing list or a database of hashed passwords. It's the raw material of identity, in a state where the driver's license is the primary ID: name, SSN, date of birth, home address, license number, registered vehicles. That's the exact bundle you need to pass an identity verification check, open a bank account, or build a credit file for a person who isn't you — and every field is permanently on file, the way it's always been. Danny Jenkins of ThreatLocker put it well: consumers treat a driver's license as a trusted proof of who you are, but every scan of one "creates another permanent copy of a credential that cannot simply be reset after a breach." The timing makes it sting more. The FBI is already probing a separate underground service, Nexus, that was selling more than 153 million digital scans of US and Canadian licenses collected through identity-verification providers. Driver-license data has become a market, and state DMV databases are the mine it keeps getting mined from.

Source article image
Source image 1

The operational lesson is the part that should worry anyone who runs a system with broad external access. DAVID exists because thousands of agencies and individual officers across the state (and beyond) need to look things up, which means the security of the entire system inherits the security habits of its weakest individual user — in this case, a small-town police department storing a high-value login on a personal device. MFA on the portal side doesn't help once the attacker is *you*: the legitimate account, the legitimate permissions, no anomalous footprint at all. The pra

Source article image
Source image 2
ctical question nobody in Florida seems to have answered yet is what a lookup system like this does at scale — credential hygiene? session analytics? per-lookup quotas that would make bulk harvesting stand out? — when the blast radius of a single account is a state's worth of identities. If you administer a system where one login can open the firehose, how would you even notice someone draining it?

Sources

Comments

Popular posts from this blog

AI Is Starting to Feel Less Like a Gadget and More Like Infrastructure

When Two AI Bots Finally Learned to Talk in Discord

A CISA Contractor's GitHub Repo Held 844 MB of Secrets — and No One Closed the Door