Severity Daily

IT and AI security incidents, checked against the primary source

Tag: credential theft

  • Florida’s motor vehicle agency confirms its law enforcement driver database was breached, and names no number

    Florida’s motor vehicle agency confirms its law enforcement driver database was breached, and names no number

    Florida’s motor vehicle agency has confirmed that its law enforcement driver database was breached, says the access came through credentials a Plant City police employee had stored on a personal device, and puts no number on what was taken — every figure in circulation belongs to the group that claimed the breach.

    What happened

    The Florida Department of Highway Safety and Motor Vehicles confirmed the breach publicly on September 10, 2026, six days after it says it learned of the incident. Its statement, verbatim and in full: “On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization. The data breach was quickly mitigated and no further breach has occurred or is ongoing.”

    The system involved is DAVID, the Driver and Vehicle Information Database, which law enforcement and criminal justice users across Florida query for driver and vehicle records. It is not public-facing; access is granted to authorized users at police departments, sheriff’s offices, and other agencies under agreements with the state.

    The agency’s account of how the access happened is specific, and it points outward. FLHSMV says its investigation found that the intruders used the login credentials of an employee of the Plant City Police Department, and that the employee had improperly stored those credentials on a personal electronic device. FLHSMV also says it has provided the required notice of the security breach to the Florida Attorney General’s Office under state law, and that the matter remains under criminal investigation.

    What the agency does not say is as important. It names no number of records or people, no categories of data, and no group. It does not say when the access began or how long it lasted, and as of this writing it has made no public commitment to notify individuals.

    The group that claimed the breach is ShinyHunters, which added FLHSMV to its leak site on or before September 8, 2026 and warned that it would publish data if the agency did not negotiate. Its claims, which are claims and not confirmed facts: that access began September 3, that it took more than 200,000 driver records, and that those records include addresses, Social Security numbers, dates of birth, driver’s license numbers, and registered vehicle information. It posted a screenshot of a single purported DAVID record as proof of possession. Reporting at the time put its deadline at September 11, 2026 — the day after the state’s confirmation.

    CyberInsider, which covered the claim on September 8, stated plainly that it “could not independently verify ShinyHunters’ claims, the authenticity of the displayed record, or whether the data came from a direct compromise.” At that point FLHSMV had not confirmed anything.

    The two accounts do not match

    The state and the group describe different root causes, and the difference is not cosmetic.

    FLHSMV describes stolen credentials: one authorized user at a municipal police department, credentials kept where they should not have been, used by someone else. ShinyHunters describes a defect in the state’s own authentication — a password-reset flaw that let it take over multiple DMV employee accounts and an account belonging to an FBI agent, after which it says it walked through records by iterating record IDs.

    Those are not two descriptions of one event. One is a hygiene failure at a partner agency and implies nothing wrong with the portal. The other is a vulnerability in a state system that would have to be found and fixed, and that would put every other account at risk regardless of how carefully its owner handled a password. Nobody has reconciled them publicly, and FLHSMV’s statement does not address the password-reset claim at all.

    The dates are compatible but uninformative. The group says access started September 3; FLHSMV says it learned of a breach on September 4 and says nothing about when the access began. “Quickly mitigated” is doing a lot of work in a sentence that never establishes what was being mitigated, or for how long it had been running.

    Why it matters

    A state driver database is a hard target with a soft perimeter, and the perimeter is other people’s employees. DAVID’s security boundary is not one agency’s network. It is every authorized account at every local department that holds one, and every device those users touch. FLHSMV cannot patch a Plant City officer’s personal phone, cannot audit a municipal department’s device policy on its own authority, and — if its own account of the breach is correct — was compromised through a control it does not administer. That is the third-party access problem in its public-sector form, and it is worse than the commercial version, because the agencies on the other end of the agreement are sovereign in their own right.

    The data involved is also the kind that does not expire. A card number gets reissued in a week. A name, address, date of birth, driver’s license number, photograph, and signature are the record of a person, and a license number is not something most people can change on request.

    Then there is the number. The only figure anyone has is 200,000, and it came from the group doing the extorting. It appears in nearly every account of this breach, usually without the qualifier. FLHSMV has confirmed no figure at all. That arrangement is now routine enough to be a pattern rather than an accident: this publication covered IDScan.net on September 10, where the company confirmed unauthorized access and named no number while two competing figures circulated from a marketplace listing, and Greenberg Traurig on September 11, where state filings named Social Security numbers after the firm publicly described the exposure as limited. The attacker’s number fills the vacuum the confirmation leaves, and it becomes the number of record by default.

    The timing deserves a note too. The group’s deadline was September 11. The state’s confirmation landed September 10, six days after it says it learned of the breach and one day before the clock ran out. That is not evidence of bad faith — FLHSMV says a criminal investigation is underway, and agencies have legitimate reasons to wait — but the pressure that produced the disclosure also shaped its content: enough to confirm the breach, not enough to quantify it.

    Finally, the claimed access pattern is worth separating from the claimed vulnerability. Iterating through sequential record identifiers to bulk-download a database looks nothing like a detective running a plate. Whether the entry was a stolen password or a reset flaw, an authorized account pulling records in volume and in order is the signal that should have fired — and any organization running a records portal for partner agencies can look for it tonight without knowing which account here is true.

    What to do

    If your agency holds DAVID access or equivalent access to another state’s driver or criminal justice database: inventory the accounts you are responsible for, confirm which are still needed, enforce phishing-resistant multi-factor authentication on all of them, and make it an auditable rule that credentials are never stored on personal devices. Then pull per-account query volume for the past 90 days and look for accounts whose usage does not match a human caseload.

    If you run a records portal used by outside organizations: alert on sequential or near-sequential identifier access, set per-account rate limits on record retrieval, and test your own password-reset and account-recovery flow for takeover — that is the specific mechanism claimed here, and it is worth ruling out in your own system whether or not it was the route in this one.

    If you are a Florida driver: there is no individual notification from FLHSMV yet, and no confirmed list of who is affected. A credit freeze with the three bureaus is free, reversible, and the single most useful step available given that Social Security numbers are among the claimed data. Watch for a formal notice from the agency rather than acting on the figures in circulation.

    And do not carry 200,000 as a confirmed count in internal reporting. Attribute it, or leave it out.

    Sourcing note

    FLHSMV’s confirmation is the primary source for this story, and it was read through its verbatim quotation in local coverage dated September 10 and September 11, 2026 rather than from the agency directly. flhsmv.gov returned 403 to automated fetching, as did one of the television outlets carrying the statement; the agency posted its statement to X, which could not be retrieved from this environment. The quoted sentences appear identically across the outlets checked, which is reasonable but not the same as reading the agency’s own page.

    Florida’s public breach notification list could not be retrieved — the Attorney General’s data breach page returned 404 — so the filing FLHSMV says it made could not be confirmed independently, and no filing date, affected-resident count, or data-category list is available from that route. That remains unresolved.

    The attacker claims come from ShinyHunters’ leak site as reported on September 8, 2026 by BleepingComputer and CyberInsider. They are labeled as claims throughout because neither outlet verified them and CyberInsider said explicitly that it could not. No sample data was reviewed for this story and no leak site was accessed. The 200,000 figure, the September 3 start date, the data categories, and the password-reset mechanism are all the group’s assertions, and none of them has been confirmed by FLHSMV or by any other agency.

    Unresolved as of this writing: how many records and people were affected, how long the access lasted, whether a password-reset defect exists in the state’s portal, and whether individual notifications will be sent. The deadline the group set has now passed, and no confirmed publication of the data has been observed.