Florida's Driver Database Fell to One Stolen Police Login
Florida's answer to how its driver database got breached should read like a scene from a security audit gone wrong. The Florida Highway Safety and Motor Vehicles agency confirmed this week that DAVID — the Driver and Vehicle Information Database that law enforcement uses to look up pretty much anyone on the road in the state — was compromised by an "international cybercriminal organization," and the entry point was a single set of credentials: one Plant City Police Department employee's login, which had been "improperly stored on the employee's personal electronic device." That's the whole vector. No zero-day, no third-party vendor, no exotic exploit chain — just one account that opened the entire building. ShinyHunters, the extortion group claiming the breach, says it took more than 200,000 driver records and posted Jeffrey Epstein's DMV record as proof: address, Social Security number, date of birth, license number, and registered vehicles. FLHSMV says the breach was "quickly mitigated" and nothing is ongoing, but the criminal investigation is still open, and the deadline ShinyHunters set for publishing the files has already come and gone.
What makes this worse than a run-of-the-mill breach is what sits inside DAVID. It's not a marketing list or a database of hashed passwords. It's the raw material of identity, in a state where the driver's license is the primary ID: name, SSN, date of birth, home address, license number, registered vehicles. That's the exact bundle you need to pass an identity verification check, open a bank account, or build a credit file for a person who isn't you — and every field is permanently on file, the way it's always been. Danny Jenkins of ThreatLocker put it well: consumers treat a driver's license as a trusted proof of who you are, but every scan of one "creates another permanent copy of a credential that cannot simply be reset after a breach." The timing makes it sting more. The FBI is already probing a separate underground service, Nexus, that was selling more than 153 million digital scans of US and Canadian licenses collected through identity-verification providers. Driver-license data has become a market, and state DMV databases are the mine it keeps getting mined from.

The operational lesson is the part that should worry anyone who runs a system with broad external access. DAVID exists because thousands of agencies and individual officers across the state (and beyond) need to look things up, which means the security of the entire system inherits the security habits of its weakest individual user — in this case, a small-town police department storing a high-value login on a personal device. MFA on the portal side doesn't help once the attacker is *you*: the legitimate account, the legitimate permissions, no anomalous footprint at all. The pra

Sources
- Florida confirms DMV database breached via stolen police account — BleepingComputer
- ShinyHunters hackers claim breach of Florida "DAVID" DMV database — BleepingComputer
- ShinyHunters claims Florida DMV breach, puts data on the clock — CSO Online
- Did ShinyHunters Breach the Florida DMV Database? — Cyber Magazine
Comments
Post a Comment