Florida officials say an international cybercriminal organization accessed the state’s driver-record system through compromised police credentials, leaving the number of affected records and the specific data exposed unresolved. The Florida Department of Highway Safety and Motor Vehicles says it learned of the breach on September 4, contained it quickly and found no continuing unauthorized access.

The entry point was an account assigned to the Plant City Police Department, according to the agency’s account of the investigation reported by Sinclair. Credentials for the account had been stored improperly on a personal electronic device before they were compromised. The account could reach the Driver and Vehicle Information Database, or DAVID, which authorized law-enforcement and government users consult for driver and vehicle records.

For Florida drivers, the most important fact is what the state has not yet established publicly. FLHSMV has not said how many records were accessed, identified the fields involved or announced whether individual notices will be sent. A group known as ShinyHunters claimed more than 200,000 records, but Florida officials have not confirmed that figure. It should therefore be treated as an allegation, not the breach count.

FLHSMV said it notified the Attorney General’s Office and is working with the Florida Digital Service and Florida Department of Law Enforcement while the criminal investigation continues. Those agencies now must determine the scope of access, which records were viewed or copied and whether the incident triggers direct consumer notification.

What Florida law requires

Florida’s data-breach statute includes governmental entities in its notification provisions. It generally requires notice to people whose personal information was accessed, without unreasonable delay and within 30 days after determining that a breach occurred. The law allows a delay requested by law enforcement and permits notice to be withheld if an investigation, conducted with law-enforcement consultation, concludes that identity theft or financial harm is unlikely. That framework means the absence of notices today does not by itself answer whether notices will follow.

Drivers do not need to assume that every Florida license record was exposed, and the state has not advised residents to replace licenses. Still, people can review their credit reports and watch for unfamiliar accounts while the investigation proceeds. The Consumer Financial Protection Bureau explains that a free security freeze prevents prospective creditors from accessing a credit file and can make it harder for an identity thief to open a new account. A freeze must be requested separately from Equifax, Experian and TransUnion.

Residents should also be cautious about calls, texts or emails that invoke the breach and demand payment, passwords or verification codes. FLHSMV has not announced paid protection services or a deadline for drivers to act. Until the state releases a confirmed count and describes the data involved, the practical response is monitoring rather than panic—and relying on notices published through official government channels.