Florida DMV Database Breached via Stolen Police Account – Over 200K Driver Records Exposed
What Happened — The Florida Department of Highway Safety and Motor Vehicles confirmed that the DAVID driver‑license database was accessed by the ShinyHunters extortion group. Attackers used credentials belonging to a Plant City Police Department employee that had been stored on the officer’s personal device. The compromised account was used to download driver records, with the gang claiming more than 200,000 records were taken.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of unmanaged privileged credentials — a core control‑area that continuous‑monitoring programs are built to protect.
- Highlights the need for documented credential‑storage policies and evidence of enforcement to satisfy audit requirements.
- Shows how a single credential failure can cascade into a large‑scale data exposure, underscoring the importance of real‑time access‑control alerts and forensic logging.
Who Is Affected – State government agencies (DMV/transportation), law‑enforcement partners, and the 200K+ Florida residents whose driver‑license data were exposed.
Recommended Actions – Review and harden privileged‑account management: enforce multi‑factor authentication, prohibit personal‑device storage of credentials, and implement continuous monitoring of privileged‑access logs. Collect evidence of policy adherence for audit readiness. Source: BleepingComputer
Technical Notes – Attack vector: stolen credentials from a personal device (no public‑facing vulnerability disclosed). Data types accessed: personal identification, vehicle registration, and associated images. Source: same as above