Select a theme from the list.
Insights

From our experts

Latest
GitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to IntrudersGigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesGitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to IntrudersGigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update Priorities
Security Insight

Stolen Police Credentials Open Florida Driver Database to Intruders

Stolen Police Credentials Open Florida Driver Database to Intruders
Photo by Ann H on Pexels

Florida officials have confirmed unauthorized access to the state's DAVID driver database through credentials assigned to a Plant City Police Department employee. The credentials had reportedly been stored on a personal device, while the ShinyHunters group claims it extracted more than 200,000 records, a figure the state has not confirmed.

A breach of Florida's Driver and Vehicle Information Database highlights how a single mishandled account can expose a government data platform used by multiple agencies. The Florida Department of Highway Safety and Motor Vehicles said it learned of the incident on September 4 and traced the access to credentials belonging to a Plant City Police Department user.

According to the agency, the credentials had been improperly stored on the employee's personal electronic device. Officials said the breach was contained and that they had not observed continuing unauthorized access. The Florida Attorney General, Florida Digital Service and Florida Department of Law Enforcement have been brought into the investigation.

Conflicting Accounts of the Intrusion

The ShinyHunters extortion group claimed responsibility and said it stole more than 200,000 driver records. The group previously described a different route into the system, alleging that a password-reset weakness enabled access to several accounts. Florida officials have not validated that explanation or confirmed how many records were viewed or downloaded.

This distinction matters. If one stolen account was the only entry point, the incident is principally an identity-security and credential-handling failure. If attackers also abused an account-recovery weakness, the exposure could be broader and require changes to the application's authentication design.

Lessons for Government IT Teams

  • Prohibit the storage of government credentials on unmanaged personal devices.
  • Require phishing-resistant multifactor authentication for database access.
  • Restrict users to the records and functions required by their roles.
  • Alert on bulk record retrieval, sequential identifier requests and unusual login locations.
  • Regularly review accounts belonging to partner agencies and law enforcement departments.

In my view, shared government databases need controls that assume participating organizations will have different levels of security maturity. Authentication should therefore be only the first layer. Query limits, behavioral monitoring, device compliance and granular authorization can prevent one compromised user from becoming a gateway to an entire statewide repository.

The most important unanswered questions concern the volume and type of information accessed. Until those facts are established, potentially affected individuals and participating agencies cannot accurately assess the risks of identity fraud, stalking or misuse of vehicle and address data.

Talk to our team →

Latest

GitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSep 12, 2026Sogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherSep 12, 2026Stolen Police Credentials Open Florida Driver Database to IntrudersSep 12, 2026Gigabud Hides Banking Fraud Inside Android Work ProfilesSep 11, 2026Surfshark Test Server Breach Exposes the Security Gap Between Development and ProductionSep 11, 2026AI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzSep 11, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching6Scattered Spider's Cyberattack on Marks & Spencer Exposes Retail Vulnerabilities