Sun 13 Sep 2026 / 13:34 ET
Kernel
Security 3 min read

Florida motor vehicle data breach tied to credentials on personal device

Florida says stolen credentials from a Plant City Police Department user’s personal device led to a motor-vehicle data breach.

Dana Voss

By Dana Voss / Security Correspondent

Florida motor vehicle data breach tied to credentials on personal device
img: The Record

Florida officials say a Florida motor vehicle data breach began when a criminal actor used credentials belonging to one Plant City Police Department user, credentials that the Florida Department of Highway Safety and Motor Vehicles said were improperly kept on that employee’s personal electronic device.

The agency said it learned of the intrusion on September 4 and described the attackers only as an “international cybercriminal organization.” FLHSMV later publicly confirmed that a breach had occurred, according to The Record.

That account identifies an access route, not a complete forensic report. Florida has not disclosed the number of records accessed, the kinds of information involved, how long the intruders had access, or whether affected people have been notified. Until the agency supplies those details, an individual’s exposure cannot be assessed from the public record.

What did Florida say caused the motor vehicle data breach?

FLHSMV said its investigation found that an attacker took advantage of a single Plant City Police Department user’s credentials after they were improperly housed on a personal device. Credentials are the login information a system accepts to identify an authorized user. If criminals obtain a valid set, they may be able to enter as that user rather than defeat the system through a disclosed software flaw.

The department’s statement does not establish how the credentials were stolen, what systems the account could reach, or whether other accounts were involved. It also does not name the employee.

FLHSMV said it notified other Florida government offices and is working with the Florida Digital Service on the investigation. NBC News reported that the agency said the breach had been contained and that law enforcement was investigating.

What ShinyHunters claimed, and what remains unverified

A group calling itself ShinyHunters claimed it had obtained Florida motor-vehicle data before the state’s public confirmation. The group circulated an alleged image of a motor-vehicle record associated with Jeffrey Epstein as purported proof of access.

NBC News said it could not independently authenticate that image. Florida has not publicly identified ShinyHunters as responsible, confirmed the group’s claimed access, or validated any claimed record count or data sample. Those are separate questions from the state’s confirmation that a breach occurred.

  • Confirmed by FLHSMV: The agency learned of a breach on September 4 and traced the stated entry point to one Plant City Police Department user’s credentials stored on a personal device.
  • Claimed by ShinyHunters: The group said it accessed Florida motor-vehicle data and posted an alleged sample record.
  • Still unknown: The scope of the breach, data categories involved, duration of access and whether people whose data may have been involved will receive notices.

Is this connected to the IDScan driver’s-license incident?

The connection has not been established. Some security experts initially suspected a link to the separate breach involving identity-verification company IDScan, The Record reported. NBC News later said the Florida and IDScan incidents did not appear to be related.

That distinction is more than bookkeeping. A confirmed breach does not turn every data claim posted by an extortion group into fact, and it does not merge separate incidents merely because both concern driver-related information. Florida’s investigation is still the part that can answer what was accessed and who, if anyone, must be notified.

This story draws on original reporting from The Record.

More Security/

view all ↗