Future TechnologyFuture Technology
Cybersecurity

One Reused Police Password Opened Florida's Entire Driver Database

· 3 min read · By Future Technology

Key takeaways

  • Florida drivers should watch for unexpected contact referencing their driving history
  • Consider a free credit freeze with the three major bureaus
  • Never store work or government system credentials on a personal device

DAVID is Florida's Driver and Vehicle Information Database, the system state and local agencies use to look up licence and vehicle records. It is not supposed to be reachable by anyone outside law enforcement and a handful of authorised agencies. In early September 2026, the extortion group ShinyHunters got in anyway, and the way they did it says more about basic security hygiene than it does about any clever hacking.

According to ShinyHunters' own account to BleepingComputer, the group exploited a password-reset weakness that let them compromise multiple accounts inside the system. The credentials that got them furthest in belonged to a user at the Plant City Police Department, and those credentials had been stored on a personal device rather than kept inside an approved, managed environment. That single lapse, a login saved somewhere it shouldn't have been, appears to have been enough to unlock access to a state driver database.

The timeline moved fast. The breach reportedly began around 3 September 2026. Florida's Department of Highway Safety and Motor Vehicles (FLHSMV) says it learned of the incident on 4 September and moved to contain it the same day, with no further unauthorised access after that point. ShinyHunters added FLHSMV to its extortion leak site on 7 September, and the breach was publicly confirmed on 11 September. The group claims records belonging to roughly 200,000 Florida drivers were taken. FLHSMV has acknowledged an "ongoing criminal investigation" but has been notably quiet on exactly what data categories were exposed, which has drawn criticism from Florida lawmakers and privacy advocates who want a fuller accounting.

Why it matters: this breach didn't need a zero-day or a supply chain compromise, it needed one employee's login sitting somewhere unmanaged. State driver databases contain the kind of foundational identity data, names, addresses, licence numbers, that gets reused across identity verification everywhere from banks to rental applications. A relatively low-tech breach of a high-value government database is a more common failure mode than the flashy zero-days that usually make headlines, and it is often the harder one to fully prevent because it comes down to individual behaviour rather than a patch.

If you're a Florida driver, don't wait for FLHSMV to spell out whether your specific record was included. Treat any unexpected contact referencing your driving or vehicle history as suspicious, keep an eye on your credit report for new accounts, and consider a credit freeze with the three major bureaus if you want the strongest protection available for free. More broadly, if your job requires access to sensitive government systems, this is a clean example of why credentials for that access should never end up saved on a personal phone or laptop, no matter how convenient it feels in the moment.

Read more: BleepingComputer: ShinyHunters hackers claim breach of Florida DAVID DMV database, Florida Politics: FLHSMV acknowledges ongoing criminal investigation

More from Future Technology