← Blog · · df00tech

Florida Confirms DMV Database Breach Traced to Stolen Police Credentials

security-news breach

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID (Driver and Vehicle Information Database) system was breached. According to FLHSMV, the attackers used login credentials belonging to a police department employee to gain access rather than exploiting a vulnerability in the database itself.

Why It Matters

DAVID-style state DMV databases hold sensitive driver and vehicle records — names, addresses, license and registration details — and access is normally restricted to authorized law enforcement and government users. A breach via a legitimate, trusted police account rather than a technical exploit highlights that credential compromise at a third-party or partner agency can expose data far beyond that agency's own systems. Any organization that grants outside entities (police departments, contractors, partner agencies) standing access to a shared sensitive database is exposed to the same risk.

What Defenders Should Watch For

  • Audit and inventory all external/partner accounts with access to shared or centralized databases, and confirm the principle of least privilege is enforced.
  • Review authentication logs for DMV, law-enforcement information-sharing, or similar lookup systems for anomalous access patterns: logins from unusual locations/times, atypical query volume, or bulk record pulls that don't match normal casework.
  • Ensure MFA is enforced on all accounts with access to law-enforcement and government information-sharing systems, including accounts held by partner/external agencies, not just internal staff.
  • Have a process for rapid credential revocation and session termination when a partner agency reports a compromised employee account.
  • Consider anomaly detection or UEBA-style monitoring on sensitive database access to catch misuse of valid credentials, since this incident reportedly did not involve exploiting a software vulnerability.

This is a developing story and further details from FLHSMV about scope, timeline, and affected individuals have not yet been reported. For the original report, see BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.