The Florida Department of Highway Safety and Motor Vehicles, the agency that issues every driver license and vehicle registration in the state, has confirmed a data breach discovered Sept. 4, and it has not yet said how many Floridians were affected or what information was taken.
The breach was traced to a police employee's login in Plant City, near Tampa, but the agency's records cover every licensed driver and registered vehicle in Florida, including those in St. Johns County.
What the state has said
Tampa Bay 28 reported Sept. 11 that the agency's investigation found an international cybercriminal organization exploited the credentials of a single Plant City Police Department user whose login information had been improperly stored on a personal electronic device. Plant City is in Hillsborough County, near Tampa.
"The data breach was quickly mitigated and no further breach has occurred or is ongoing," the agency said in a statement carried by the station.
The department said it has given the Florida Attorney General's Office the notice state law requires, and that the Florida Digital Service and the Florida Department of Law Enforcement are assisting with the response. The incident remains under criminal investigation, and officials told the station that additional details would be released at an appropriate time.
Officials did not release details about what information may have been accessed or how many people may have been affected.
The extortion claim that came first
The Sept. 11 confirmation came three days after an unverified claim surfaced. On Sept. 8, the cybersecurity outlet CyberInsider reported that the extortion group ShinyHunters said it had pulled driver and vehicle records from DAVID, the restricted Driver and Vehicle Information Database that Florida law enforcement agencies use to look up drivers. The group had posted a screenshot of what appeared to be a DAVID record on its leak site the day before and set a Sept. 11 deadline for the state to make contact, CyberInsider reported. It told the outlet it got in through a password-reset exploit.


