Florida’s Department of Highway Safety and Motor Vehicles confirmed Thursday that its DAVID driver database was breached after ShinyHunters claimed access, and investigators traced it to a single Plant City police user credential stored on a personal device. The state said the login was legitimate, which is what let the intruder in as a trusted user instead of forcing a direct break-in.
The mechanism matters because the compromise was not of the DMV perimeter itself. A local police account that still had reach into a shared state records system became the entry point, so one exposed endpoint could be used like a pass into a backend that accepted it.
For agencies that let field staff use personal devices for privileged access, the lasting exposure is the trust relationship: any downstream system that accepts those credentials inherits the same failure mode, even when the account sits outside the core state network.