Severity Daily

IT and AI security incidents, checked against the primary source

Tag: driver’s license data

  • Florida’s motor vehicle agency confirms its law enforcement driver database was breached, and names no number

    Florida’s motor vehicle agency confirms its law enforcement driver database was breached, and names no number

    Florida’s motor vehicle agency has confirmed that its law enforcement driver database was breached, says the access came through credentials a Plant City police employee had stored on a personal device, and puts no number on what was taken — every figure in circulation belongs to the group that claimed the breach.

    What happened

    The Florida Department of Highway Safety and Motor Vehicles confirmed the breach publicly on September 10, 2026, six days after it says it learned of the incident. Its statement, verbatim and in full: “On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization. The data breach was quickly mitigated and no further breach has occurred or is ongoing.”

    The system involved is DAVID, the Driver and Vehicle Information Database, which law enforcement and criminal justice users across Florida query for driver and vehicle records. It is not public-facing; access is granted to authorized users at police departments, sheriff’s offices, and other agencies under agreements with the state.

    The agency’s account of how the access happened is specific, and it points outward. FLHSMV says its investigation found that the intruders used the login credentials of an employee of the Plant City Police Department, and that the employee had improperly stored those credentials on a personal electronic device. FLHSMV also says it has provided the required notice of the security breach to the Florida Attorney General’s Office under state law, and that the matter remains under criminal investigation.

    What the agency does not say is as important. It names no number of records or people, no categories of data, and no group. It does not say when the access began or how long it lasted, and as of this writing it has made no public commitment to notify individuals.

    The group that claimed the breach is ShinyHunters, which added FLHSMV to its leak site on or before September 8, 2026 and warned that it would publish data if the agency did not negotiate. Its claims, which are claims and not confirmed facts: that access began September 3, that it took more than 200,000 driver records, and that those records include addresses, Social Security numbers, dates of birth, driver’s license numbers, and registered vehicle information. It posted a screenshot of a single purported DAVID record as proof of possession. Reporting at the time put its deadline at September 11, 2026 — the day after the state’s confirmation.

    CyberInsider, which covered the claim on September 8, stated plainly that it “could not independently verify ShinyHunters’ claims, the authenticity of the displayed record, or whether the data came from a direct compromise.” At that point FLHSMV had not confirmed anything.

    The two accounts do not match

    The state and the group describe different root causes, and the difference is not cosmetic.

    FLHSMV describes stolen credentials: one authorized user at a municipal police department, credentials kept where they should not have been, used by someone else. ShinyHunters describes a defect in the state’s own authentication — a password-reset flaw that let it take over multiple DMV employee accounts and an account belonging to an FBI agent, after which it says it walked through records by iterating record IDs.

    Those are not two descriptions of one event. One is a hygiene failure at a partner agency and implies nothing wrong with the portal. The other is a vulnerability in a state system that would have to be found and fixed, and that would put every other account at risk regardless of how carefully its owner handled a password. Nobody has reconciled them publicly, and FLHSMV’s statement does not address the password-reset claim at all.

    The dates are compatible but uninformative. The group says access started September 3; FLHSMV says it learned of a breach on September 4 and says nothing about when the access began. “Quickly mitigated” is doing a lot of work in a sentence that never establishes what was being mitigated, or for how long it had been running.

    Why it matters

    A state driver database is a hard target with a soft perimeter, and the perimeter is other people’s employees. DAVID’s security boundary is not one agency’s network. It is every authorized account at every local department that holds one, and every device those users touch. FLHSMV cannot patch a Plant City officer’s personal phone, cannot audit a municipal department’s device policy on its own authority, and — if its own account of the breach is correct — was compromised through a control it does not administer. That is the third-party access problem in its public-sector form, and it is worse than the commercial version, because the agencies on the other end of the agreement are sovereign in their own right.

    The data involved is also the kind that does not expire. A card number gets reissued in a week. A name, address, date of birth, driver’s license number, photograph, and signature are the record of a person, and a license number is not something most people can change on request.

    Then there is the number. The only figure anyone has is 200,000, and it came from the group doing the extorting. It appears in nearly every account of this breach, usually without the qualifier. FLHSMV has confirmed no figure at all. That arrangement is now routine enough to be a pattern rather than an accident: this publication covered IDScan.net on September 10, where the company confirmed unauthorized access and named no number while two competing figures circulated from a marketplace listing, and Greenberg Traurig on September 11, where state filings named Social Security numbers after the firm publicly described the exposure as limited. The attacker’s number fills the vacuum the confirmation leaves, and it becomes the number of record by default.

    The timing deserves a note too. The group’s deadline was September 11. The state’s confirmation landed September 10, six days after it says it learned of the breach and one day before the clock ran out. That is not evidence of bad faith — FLHSMV says a criminal investigation is underway, and agencies have legitimate reasons to wait — but the pressure that produced the disclosure also shaped its content: enough to confirm the breach, not enough to quantify it.

    Finally, the claimed access pattern is worth separating from the claimed vulnerability. Iterating through sequential record identifiers to bulk-download a database looks nothing like a detective running a plate. Whether the entry was a stolen password or a reset flaw, an authorized account pulling records in volume and in order is the signal that should have fired — and any organization running a records portal for partner agencies can look for it tonight without knowing which account here is true.

    What to do

    If your agency holds DAVID access or equivalent access to another state’s driver or criminal justice database: inventory the accounts you are responsible for, confirm which are still needed, enforce phishing-resistant multi-factor authentication on all of them, and make it an auditable rule that credentials are never stored on personal devices. Then pull per-account query volume for the past 90 days and look for accounts whose usage does not match a human caseload.

    If you run a records portal used by outside organizations: alert on sequential or near-sequential identifier access, set per-account rate limits on record retrieval, and test your own password-reset and account-recovery flow for takeover — that is the specific mechanism claimed here, and it is worth ruling out in your own system whether or not it was the route in this one.

    If you are a Florida driver: there is no individual notification from FLHSMV yet, and no confirmed list of who is affected. A credit freeze with the three bureaus is free, reversible, and the single most useful step available given that Social Security numbers are among the claimed data. Watch for a formal notice from the agency rather than acting on the figures in circulation.

    And do not carry 200,000 as a confirmed count in internal reporting. Attribute it, or leave it out.

    Sourcing note

    FLHSMV’s confirmation is the primary source for this story, and it was read through its verbatim quotation in local coverage dated September 10 and September 11, 2026 rather than from the agency directly. flhsmv.gov returned 403 to automated fetching, as did one of the television outlets carrying the statement; the agency posted its statement to X, which could not be retrieved from this environment. The quoted sentences appear identically across the outlets checked, which is reasonable but not the same as reading the agency’s own page.

    Florida’s public breach notification list could not be retrieved — the Attorney General’s data breach page returned 404 — so the filing FLHSMV says it made could not be confirmed independently, and no filing date, affected-resident count, or data-category list is available from that route. That remains unresolved.

    The attacker claims come from ShinyHunters’ leak site as reported on September 8, 2026 by BleepingComputer and CyberInsider. They are labeled as claims throughout because neither outlet verified them and CyberInsider said explicitly that it could not. No sample data was reviewed for this story and no leak site was accessed. The 200,000 figure, the September 3 start date, the data categories, and the password-reset mechanism are all the group’s assertions, and none of them has been confirmed by FLHSMV or by any other agency.

    Unresolved as of this writing: how many records and people were affected, how long the access lasted, whether a password-reset defect exists in the state’s portal, and whether individual notifications will be sent. The deadline the group set has now passed, and no confirmed publication of the data has been observed.

  • IDScan.net confirms unauthorized access to its cloud and names no number — every figure in circulation comes from the marketplace that sold the data

    IDScan.net confirms unauthorized access to its cloud and names no number — every figure in circulation comes from the marketplace that sold the data

    The company’s own notice confirms unauthorized access and gives no figure at all; the 153 million and 170 million numbers in circulation come from the criminal marketplace that offered the data, and from a researcher who searched it.

    What happened

    What changed, and when: IDScan.net published a notice titled “Notification of Data Security Incident,” dated September 4, 2026, confirming that customer data held in its cloud may have been accessed by an unauthorized party. Severity Daily is writing it up on September 10 because the confirmation is the primary-source event here, and because the numbers attached to it in wide circulation this week are not the company’s.

    The notice is short and hedged. It says that “on or around September 1, 2026, IDScan.net received information indicating that certain data may have been accessed without authorization,” and that the company determined “an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud.” The data “may include full names and driver’s license or other government-issued identification numbers.” IDScan says it “took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope,” and that it is “cooperating with federal law enforcement on their investigation.” It offers free credit monitoring and identity protection, and advises “potentially impacted individuals” to review credit reports and account statements.

    The notice names no number. Not a record count, not an individual count, not a per-state count. It does not say whether license images were included, and it does not name which of the company’s customers were affected.

    Where the numbers come from

    Every figure circulating this week originates outside the company.

    The largest set comes from the criminal marketplace itself. A dark-web service calling itself Nexus advertised a searchable database and claimed more than 153 million United States and Canadian driver’s licenses, more than 10 million identification cards, more than 3 million travel documents, and more than 579,000 medical cards. That is an attacker’s sales claim, and it should be read as one. The 170 million figure that has appeared in headlines is the sum of those claimed document classes, not a separate finding.

    The strongest independent evidence of scale is Brian Krebs’s own reporting, and it is a researcher’s count rather than a company disclosure. Krebs was alerted to the Nexus service on August 31, 2026, and reported that a blank search returned roughly 11.5 million pages at about 15 results per page. He wrote that he located his own license in the database along with those of nine friends and family members, with timestamps matching travel or car-rental dates. That is direct verification of the data’s authenticity and rough order of magnitude by someone who searched it. It is not an audited count, and Krebs does not present it as one.

    Krebs also reported that the FBI’s New Orleans field office opened an investigation, and that he took part in a call with bureau cyber-division staff on September 1, 2026. The Nexus site went offline on September 2, 2026 at 6:05 p.m.

    Two things the record does not agree on

    When the notice appeared. The page itself carries the date September 4, 2026. Krebs’s account has IDScan publishing the notice on September 8. We could not resolve which is the publication date and which is the drafting date, and the page does not carry a revision history.

    Whether the company has said anything at all. Reporting on the resulting lawsuits, published this week, states that IDScan “has not published any statements about these allegations, and it did not respond to BleepingComputer’s requests for comments.” The notice quoted above was live on idscan.net when we read it this afternoon. Those two things can both be true — a company can post a breach notice and still decline to comment on litigation — but a reader following the coverage would reasonably conclude the company has been silent, and it has not been. Where coverage and the primary source diverge, the primary source is the notice.

    Separately, when Krebs approached the company before the notice, a named IDScan representative told him: “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.”

    Why it matters

    This is a breach of an identity-verification vendor, which makes the exposed material qualitatively different from the usual email-and-hashed-password set. IDScan’s product exists to read government identity documents at a point of sale or a rental counter; the data it holds is by definition the data used to prove that a person is who they say they are. Reporting on the company’s customer base describes car rental firms, retailers, gun shops, financial institutions, cannabis dispensaries and hospitality businesses, with Hertz named. Every one of those is a place where a consumer hands over a license as a condition of the transaction and has no visibility into where the scan goes afterward, or how long it is kept.

    That is the structural point worth carrying away, and it does not depend on which number turns out to be right. The people in this data set are not IDScan’s customers. They are their customers’ customers, and in most cases they will never have heard the vendor’s name. The notice’s advice — review your credit reports — is the only advice available, and it is advice addressed to people who cannot check whether they are in the set, because the company that holds the set has not said who is in it.

    The number vacuum has a second-order effect that is already visible. When the affected organization publishes no figure, the attacker’s figure becomes the headline figure by default, and it propagates into litigation, into regulatory attention and into every subsequent story as though it were established. It may well be roughly right — Krebs’s search results point that way. But “roughly right, sourced to the seller” is a different epistemic object from “confirmed by the holder,” and once the two are conflated in print they are very hard to separate again. This publication’s standing practice is to show conflicting numbers as conflicting rather than pick one, and here the conflict is not between two counts. It is between a count and an absence.

    The route that normally resolves this is the state breach-notification system, which forces a per-state resident count into a public filing. That route is partly closed right now. Maine’s public breach-notice database — usually the fastest searchable source for a hard number — is offline, with the state directing queries to an email address. California’s published list showed no IDScan entry when we checked this afternoon. Whether that reflects no filing yet, a filing not yet posted, or notification still in progress, we cannot say.

    What to do

    If you are an IDScan customer — a business that used the platform to scan identity documents — ask the vendor directly, in writing, whether your account’s stored records are in scope and for what date range, and ask specifically whether images as well as document numbers were involved. The public notice answers neither question. Treat the answer as a notification obligation trigger for your own customers, and get counsel involved on the timing rules in every state you operate in.

    If you handle identity documents through any vendor, this is the week to establish what your provider retains after a verification completes, for how long, and whether images are stored or discarded once the document number is read. Retention is the variable that turned a scanning service into a 150-million-record repository, and it is a contract term, not a technical one.

    For individuals, a driver’s license number is not rotatable the way a password is. Credit monitoring detects misuse after the fact; a credit freeze at the three bureaus prevents new-account fraud, is free, and is the stronger control. Some states allow a license number to be reissued after documented identity theft — a question for your own motor vehicle agency.

    Sourcing note

    Checked directly: IDScan.net’s own “Notification of Data Security Incident,” dated September 4, 2026, for every statement attributed to the company, including the absence of any figure; Krebs on Security’s September 1, 2026 report for the Nexus marketplace’s claimed document counts, the search-result estimate, the personal verification, the FBI New Orleans investigation and the site’s removal on September 2; TechCrunch’s September 10 report and BleepingComputer’s litigation report as leads and as the source of the “has not published any statements” characterization; the California Attorney General’s published breach list, which showed no IDScan entry; and Maine’s breach-notice database, which is offline.

    Not established: the number of affected individuals or records; whether license images were exposed; which IDScan customers are in scope; the number, court and filing dates of the lawsuits, which we could not confirm from a primary docket; and the true publication date of the notice. No attribution to any named actor or group is made here — the Nexus operators’ identity is unknown, and the marketplace’s claims about what it held are claims. IDScan has confirmed unauthorized access. It has not confirmed scale.