Florida’s driver-record agency says an international cybercriminal organization breached a state database by using login credentials issued to a Plant City Police Department user and stored improperly on a personal electronic device. The Florida Department of Highway Safety and Motor Vehicles said in its agency statement that it learned of the intrusion Sept. 4, contained it quickly and has seen no further or ongoing breach.
The incident matters statewide because the compromised account reached the Driver and Vehicle Information Database, known as DAVID. Authorized law-enforcement and government users rely on that system to retrieve driver and vehicle records. A local report said the agency traced the access to one Plant City police user’s credentials, making credential handling — rather than a publicly disclosed flaw in the state platform — the confirmed entry point so far.
Important questions remain unanswered. FLHSMV has not publicly identified how many people were affected, which fields were viewed or copied, how long the unauthorized access lasted, or whether individual notices will be required. A cybercriminal group has claimed more than 200,000 driver records, but coverage of the claim notes that Florida has not confirmed that figure. Treating the number as established would therefore go beyond the public record.
The department said it notified the Florida attorney general and is working with the Florida Digital Service and the Florida Department of Law Enforcement while the criminal investigation continues. That notice has legal significance. Florida’s breach statute defines a breach as unauthorized access to electronic data containing personal information, requires notice to the Department of Legal Affairs when at least 500 Floridians are affected, and generally requires notice to individuals whose personal information was accessed. The statute allows a delay if law enforcement says notification would interfere with an investigation.
For residents, the absence of a confirmed record count or notification schedule means the practical risk cannot yet be measured from public information. The law requires any individual notice to describe when the breach occurred, what personal information was accessed or reasonably believed to have been accessed, and how to contact the entity holding the data. Until FLHSMV publishes those details, residents should distinguish the state’s confirmed facts — compromised local credentials, access to DAVID and containment — from the attacker’s unverified claims about volume.
The episode also exposes a governance problem that extends beyond one account. A statewide database can be protected centrally while still depending on security practices at every authorized local endpoint. The continuing investigation will need to establish what was taken, whether other credentials were tested, and whether access controls or monitoring should change. Those findings, rather than the attacker’s publicity, will determine the breach’s actual scale and what Florida must do next.