Key Takeaways

  • Compromised Plant City Police Department credentials exposed roughly 200,000 DAVID records to potential theft.
  • ShinyHunters claims a password-reset weakness helped it compromise additional accounts and extract data.
  • The incident highlights identity, credential-storage, and access-monitoring gaps across public-sector systems.

The Florida Highway Safety and Motor Vehicles department has contained unauthorized access to its Driver and Vehicle Information Database, or DAVID, after credentials assigned to a Plant City Police Department employee were compromised. The intrusion placed roughly 200,000 driver records at risk, including driver license information, Social Security numbers, and home addresses.

According to WCTV, Florida Highway Safety and Motor Vehicles said an international cybercriminal group obtained credentials that had been improperly stored on the employee's personal device. The department said the incident is no longer ongoing. That containment matters, but it does not settle the larger questions around what data was extracted, how affected people will be notified, or whether stolen information will circulate through criminal markets.

There may also have been more than one weakness involved. ShinyHunters, an extortion group associated with high-profile data theft claims, says it exploited a password-reset flaw to take control of multiple DAVID accounts. BleepingComputer reported that the group claimed it iterated through driver IDs and stole more than 200,000 records before losing access. Florida reportedly patched the weakness and cut off the intrusion.

Claims from an extortion group warrant caution. Attackers can exaggerate the scope of an incident to increase pressure on victims. Still, the overlap between the group's account and Florida Highway Safety and Motor Vehicles' confirmation points to a serious access-control failure, even if the final forensic assessment changes the record count or details of the attack path.

DAVID is not simply another departmental application. It gives authorized users access to identity information that can support law enforcement and other government functions. That makes individual accounts unusually valuable. If one compromised credential can expose a large pool of records, security depends not only on perimeter defenses but also on tight limits around what each user can view, how quickly unusual activity is detected, and how account recovery is handled.

The personal-device detail is especially important for business and technology leaders. Credentials saved outside managed environments can escape controls such as endpoint monitoring, device encryption, password policies, and remote revocation. Phishing-resistant multifactor authentication can reduce some of that exposure, while conditional-access policies can block logins from unmanaged devices or unexpected locations. Neither measure is perfect. Together with short session lifetimes and behavioral monitoring, however, they can make stolen credentials less useful.

Password resets deserve equal scrutiny. Recovery processes are often treated as a usability function, yet they can become a route around otherwise strong authentication. Can an attacker reset an account with information obtained elsewhere? Can reset requests be automated across many identities? Those are design questions, not merely help-desk concerns.

The Florida incident also fits a broader public-sector pattern. IndustrialCyber reported that major cyberattacks affected state and local governments in at least 44 states during 2025. Separate figures in the Kansas Legislative Research Department's 2026 briefing materials indicate that cyberattacks on state and local governments rose 48% between 2023 and 2024, with 34% reporting ransomware incidents. A 2025 to 2026 national scan identified 276 ransomware attacks against U.S. government entities in Q1 through Q3 2025, breaching at least 443,000 records.

That said, this DAVID incident has been described as unauthorized access and data theft, not a confirmed ransomware deployment. The distinction matters operationally. Data-extortion attacks can leave services running normally while exposing residents to identity theft, targeted phishing, impersonation, and physical-security risks associated with leaked home addresses.

Florida Highway Safety and Motor Vehicles now faces a longer remediation cycle than simply closing the exploited path. Account privileges can be reassessed, password-reset activity reviewed, dormant access removed, and high-volume record lookups flagged in near real time. Identity products such as Okta and Microsoft Entra ID, along with monitoring and data-protection technology from vendors including Palo Alto Networks, can support that work, but configuration and governance remain central.

For other government organizations, the warning is fairly direct. A statewide database can inherit risk from every authorized endpoint and partner account connected to it. Containment ends the active intrusion. Reducing the chance of a repeat requires stronger credential hygiene, narrower access, and audit systems capable of spotting when a legitimate account starts behaving like an attacker.