The Florida Department of Highway Safety and Motor Vehicles has confirmed an unauthorized intrusion into its statewide Driver and Vehicle Information Database, commonly known as DAVID. The system, which serves as a central repository for state driver licenses, vehicle records, and personal identification data, was accessed following an account compromise linked to an external law enforcement user.
How the Breach Occurred
According to state investigators, the breach originated from compromised login credentials belonging to an officer with the Plant City Police Department. The credentials were reportedly stored improperly on an unsecured personal electronic device, allowing threat actors to harvest the authentication details and gain unauthorized entry into the restricted portal.
While state authorities moved rapidly to isolate and revoke the compromised session, the international extortion syndicate known as ShinyHunters claimed responsibility for the intrusion. The cybercriminal group alleged it had downloaded more than 200,000 driver files by systematically querying record identification numbers. While state officials have not validated the exact number of compromised records, they confirmed that an inter-agency investigation involving the Florida Digital Service and state law enforcement remains underway.
What Data Was Exposed & Consumer Risks
Law enforcement portals like DAVID house sensitive demographic, biometric, and vehicular information. Exposure of these files creates several immediate hazards for affected drivers:
- Personal Identifiers: Driver license numbers, full legal names, residential addresses, and dates of birth can facilitate synthetic identity creation or loan fraud.
- Facial and Biometric Data: High-resolution driver license photos can be utilized by scammers to bypass identity verification controls on banking and crypto exchanges.
- Vehicle Records: Vehicle identification numbers (VINs), license plates, and registration details allow criminals to launch highly convincing automotive warranty or toll fee scams.
- Targeted Phishing and Impersonation: Leaked details empower extortionists to craft believable communications impersonating government entities, traffic courts, or financial institutions.
Protective Steps for Affected Consumers
Florida drivers should assume their information may circulate among illicit marketplaces and take proactive security measures immediately to mitigate potential exploitation.
- Freeze Your Credit: Place an immediate freeze on your credit files with Experian, Equifax, and TransUnion to prevent unauthorized accounts or loans from being opened in your name.
- Monitor Driver and Vehicle Records: Check your Florida driving history and vehicle registration status periodically for unauthorized address changes or duplicate plate requests.
- Scrutinize Traffic and DMV Communications: Be wary of unsolicited text messages or emails claiming you owe unpaid tolls, citations, or license renewal fees, as attackers routinely leverage DMV leaks to direct victims to phishing portals.
- Activate Identity Theft Monitoring: Consider utilizing dark web monitoring tools to receive real-time alerts if your driver license number or Social Security number surfaces in public leak dumps.