Florida DMV Breach Traced to Plant City Officer

Florida’s Department of Highway Safety and Motor Vehicles says an international cybercriminal organization broke into the state’s driver database earlier this month by exploiting login credentials belonging to a single Plant City police employee that had been stored improperly on a personal electronic device. The agency says it detected and mitigated the intrusion quickly after learning of it on last Friday and that there is no ongoing breach.

State Says the Breach Was Isolated to One Officer’s Device

According to Tampa Bay 28, FLHSMV’s investigation determined that the international group exploited the credentials of just one Plant City Police Department user to get into the system. The agency has provided the required security-breach notice to the Florida Attorney General’s Office and says the matter remains under criminal investigation, with FLHSMV working alongside the Florida Department of Law Enforcement and the Florida Digital Service. Officials have not released a count of how many people were affected or details about what information was accessed, saying only that additional information will be released at an appropriate time in the future, per the same report.

That account stands in sharp contrast to what the hackers themselves are claiming. The extortion group ShinyHunters listed the Florida DMV on its dark web leak site on September 7, setting a deadline of Friday and claiming to have stolen more than 200,000 driver records, according to BleepingComputer. The group posted a final warning threatening to release the files if state officials did not negotiate.

Hackers Published Jeffrey Epstein’s DMV Record as Proof

To back up its claims, ShinyHunters published a screenshot of late financier Jeffrey Epstein’s driver record pulled from Florida’s DAVID system, exposing his photo, signature, Social Security number, driver’s license ID, address, and registered vehicles, as reported by Cyber Magazine. The published sample matched the standard user interface layout of Florida’s DAVID system, according to that outlet.

The hackers and the state also disagree on how the intrusion happened in the first place. Threat actors claimed they exploited a password-reset vulnerability affecting multiple user accounts and told reporters they had compromised accounts belonging to DMV employees and an FBI agent, according to CSO Online. FLHSMV, however, reported that the breach traced back to credentials improperly stored on the single Plant City officer’s personal device, per Tampa Bay 28’s reporting. Neither version has been reconciled publicly, and the discrepancy remains unresolved.

Why the DAVID Database Carries So Much Weight

The Driver and Vehicle Information Database, known as DAVID, is governed by the federal Driver’s Privacy Protection Act and Florida Statutes Section 119.0712(2), which gives authorized law enforcement agencies real-time access to driver photos, signatures, Social Security numbers, emergency contacts, and crash histories, according to Online Sunshine. State officials describe DAVID as an indispensable tool for daily police lookups and traffic stops, which is part of why a single compromised login can carry such wide-reaching consequences…

Story continues

TRENDING NOW

LATEST LOCAL NEWS