Florida database breached; Incident not ongoing, state agency confirms | #cybercrime | #infosec


TALLAHASSEE, Fla. (WCTV/Gray Florida Capital Bureau) – Florida’s database was breached by an international cybercriminal organization, according to the Florida Highway Safety and Motor Vehicles (FLHSMV).

Thursday, the Florida Capitol Bureau initially reported that state officials had no official confirmation of the breach, though multiple cybercrime monitoring websites said the database may have been hacked.

However, later that evening, FLHSMV confirmed the hack in a statement, saying the department learned of the breach on Sept. 4 and quickly mitigated it. Additionally, the agency said there has been no further breach and that the incident is not ongoing.

The department’s investigation revealed that a criminal actor gained access using the credentials of a single Plant City Police Department employee. Those credentials were improperly stored on the employee’s personal electronic device, per FLHSMV.

Now, the agency is working with the Florida Digital Service and the Florida Department of Law Enforcement as part of its response. The department also said it has notified the Florida Attorney General’s Office, as required by state law.

The breach was first reported by multiple cybercrime monitoring websites, which said a group identifying itself as “ShinyHunters” claimed responsibility. The group is well known for this type of attack.

Prior to the breach’s confirmation, University of South Florida Cybercrime Professor Thomas Hyslip said the reports appeared credible.

Furthermore, Hyslip said “ShinyHunters” generally tells the truth when it claims to have stolen data. If they didn’t, they wouldn’t get paid again. In this case, they say they have about 200,000 driver’s licenses, Social Security numbers and home addresses.

“So, they’re a financially motivated cyber actor,” the professor said. “Historically, they try to hack systems, steal data and then try to extort the victim into paying a ransom.”

While state officials did not go into detail about what was accessed, they did say it is still an ongoing investigation.

Earlier this year, Microsoft and Google warned users that the group “ShinyHunters” could exploit vulnerabilities in software.

A source who interacts with the DAVID system every day said the state government sent down some guidance Wednesday about who can use the system and for what purpose.

The source said that is very unusual.

Hyslip said if you fear your driver’s license or other personal data is compromised, the best thing to do is freeze your credit with each of the credit bureaus.

Frankly, Hyslip said almost everyone’s “personally identifying information” is already on the dark web somewhere, so freezing your credit in general is a good idea.

Copyright 2026 WCTV. All rights reserved.



Click Here For The Original Source.

——————————————————–

..........

.

.