Florida State Driver Database Breached Through Unsecured Police Device
Tallahassee, Saturday, 12 September 2026.
Hackers accessed Florida’s driver database using stolen police credentials saved on a personal phone. The attack exposes systemic vulnerabilities in public infrastructure, putting over 200,000 records at risk.
Breach Confirmation and Timeline
On September 11, 2026, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) publicly confirmed a cybersecurity breach affecting its Driver and Vehicle Information Database (DAVID) [1][5]. The agency stated it first detected the intrusion on September 4, 2026, attributing the attack to an international cybercriminal organization [3][5]. This incident marks the second major compromise of driver’s license data in the United States within the same month, following a separate breach reported by vendor IDscan.net [1]. The hacking group ShinyHunters claimed responsibility for the FLHSMV breach, setting a deadline of September 11, 2026, for the state to negotiate [1][4]. While the deadline has passed, it remains unconfirmed if the state negotiated, though ShinyHunters removed references to Florida from their site on September 4, 2026 [1].
Systemic Vulnerabilities in Access Control
The department’s investigation revealed that a criminal actor gained access using the credentials of a single Plant City Police Department employee [3]. Those credentials were improperly stored on the employee’s personal electronic device, violating state policy [3][5]. Security analysis identifies the DAVID system as utilizing a legacy single-factor, username-and-password-based authentication model [5]. This model lacks modern phishing-resistant multi-factor authentication (MFA) standards like FIDO2 hardware security keys used by federal agencies [5]. ShinyHunters claimed to have exploited a password-reset vulnerability, though FLHSMV states the incident involved a single stolen credential [2][5].
Political Response and Budgetary Measures
Governor Ron DeSantis proposed $16 million in the Fiscal Year 2025-26 budget for a Motorist Modernization initiative intended to enhance motor vehicle licensing efficiency [4]. State officials allegedly failed to address a known system vulnerability prior to the exploit, which potentially enables attackers to bypass identity verification safeguards [4]. This incident is distinct from a separate, ongoing FBI-investigated breach involving 153 million driver’s licenses sourced from a Louisiana-based identity verification company [4]. The scale of the Florida breach is significantly smaller, with claims of 200,000 records compared to the 153 million in the IDscan incident [1][2][4]. The relative size is 0.131 percent of the IDscan breach volume [1][2].
Consumer Risks and Mitigation
The compromised data potentially includes images, addresses, dates of of birth, and vehicle identification numbers, which could facilitate identity fraud [4]. University of South Florida Cybercrime Professor Thomas Hyslip noted that if personal data is compromised, the best action is to freeze credit with each of the credit bureaus [3]. Hyslip added that almost everyone’s personally identifying information is already on the dark web somewhere, so freezing credit is generally advisable [3]. The breach highlights recurring vulnerabilities in state-run databases, which are prime targets for fraud rings due to verified identity data [5].