Overview
- The Florida Department of Highway Safety and Motor Vehicles says it learned of the breach on Sept. 4 and traced access to credentials belonging to a single Plant City Police Department user that were improperly stored on a personal electronic device.
- The hacker group ShinyHunters publicly claimed it stole more than 200,000 DAVID records and posted a screenshot as proof, but FLHSMV has not confirmed the number of records taken and disputes the group’s reported access method.
- FLHSMV says the intrusion was quickly contained, it has notified the Florida attorney general and state digital and law-enforcement partners, and it is working with federal authorities as the criminal probe continues.
- DAVID holds highly sensitive personally identifying information — including names, addresses, dates of birth, Social Security numbers, driver’s license IDs, vehicle records and images — which raises clear risks of identity theft if data are released.
- Security coverage links this incident to wider vulnerabilities in DMV and third-party systems, noting a recent large drivers-license data set tied to an identity-verification vendor is under FBI review and that the hackers removed public references to Florida after the state’s statement.