Tampa/ Crime & Emergencies

Florida DMV Breach Traced to Plant City Officer

AI Assisted Icon
Published on September 11, 2026
Florida DMV Breach Traced to Plant City OfficerSource: Google Street View

Florida's Department of Highway Safety and Motor Vehicles says an international cybercriminal organization broke into the state's driver database earlier this month by exploiting login credentials belonging to a single Plant City police employee that had been stored improperly on a personal electronic device. The agency says it detected and mitigated the intrusion quickly after learning of it on last Friday and that there is no ongoing breach.

State Says the Breach Was Isolated to One Officer's Device

According to Tampa Bay 28, FLHSMV's investigation determined that the international group exploited the credentials of just one Plant City Police Department user to get into the system. The agency has provided the required security-breach notice to the Florida Attorney General's Office and says the matter remains under criminal investigation, with FLHSMV working alongside the Florida Department of Law Enforcement and the Florida Digital Service. Officials have not released a count of how many people were affected or details about what information was accessed, saying only that additional information will be released at an appropriate time in the future, per the same report.

That account stands in sharp contrast to what the hackers themselves are claiming. The extortion group ShinyHunters listed the Florida DMV on its dark web leak site on September 7, setting a deadline of Friday and claiming to have stolen more than 200,000 driver records, according to BleepingComputer. The group posted a final warning threatening to release the files if state officials did not negotiate.

Hackers Published Jeffrey Epstein's DMV Record as Proof

To back up its claims, ShinyHunters published a screenshot of late financier Jeffrey Epstein's driver record pulled from Florida's DAVID system, exposing his photo, signature, Social Security number, driver's license ID, address, and registered vehicles, as reported by Cyber Magazine. The published sample matched the standard user interface layout of Florida's DAVID system, according to that outlet.

The hackers and the state also disagree on how the intrusion happened in the first place. Threat actors claimed they exploited a password-reset vulnerability affecting multiple user accounts and told reporters they had compromised accounts belonging to DMV employees and an FBI agent, according to CSO Online. FLHSMV, however, reported that the breach traced back to credentials improperly stored on the single Plant City officer's personal device, per Tampa Bay 28's reporting. Neither version has been reconciled publicly, and the discrepancy remains unresolved.

Why the DAVID Database Carries So Much Weight

The Driver and Vehicle Information Database, known as DAVID, is governed by the federal Driver's Privacy Protection Act and Florida Statutes Section 119.0712(2), which gives authorized law enforcement agencies real-time access to driver photos, signatures, Social Security numbers, emergency contacts, and crash histories, according to Online Sunshine. State officials describe DAVID as an indispensable tool for daily police lookups and traffic stops, which is part of why a single compromised login can carry such wide-reaching consequences.

Agencies that tap into the network are required to sign a Memorandum of Understanding mandating strict physical security and password controls to prevent unauthorized access, according to PowerDMS. Storing a user's login information on an unapproved personal device, as FLHSMV says happened in this case, would violate those operational access agreements.

Legal Exposure and Possible Penalties

Under federal law, specifically 18 U.S.C. Section 2724, individuals whose motor vehicle records are impermissibly accessed or disclosed from state databases can file civil lawsuits for actual damages or liquidated damages of at least $2,500 per violation, plus attorney fees and punitive damages, according to RumbergerKirk. The Driver's Privacy Protection Act creates a private right of action for victims of unauthorized access, meaning affected drivers could pursue claims once the scope of the breach becomes clearer.

Florida law also spells out administrative and criminal consequences for improper handling of DAVID data. Under Florida Statute Section 119.0712(2)(e), unauthorized use or release of DAVID information is a noncriminal infraction punishable by a fine of up to $2,000, while intentional misuse by officers can trigger a first-degree misdemeanor charge and suspension under Section 119.10, per Online Sunshine. Separately, the Florida Information Protection Act requires state agencies to notify the Attorney General's Office and affected residents within 30 days of determining a breach occurred, a requirement FLHSMV says it has already met by notifying the Attorney General's Office.

A Familiar Pattern of Database Misuse and Attacks

This is not the first time DAVID access has drawn scrutiny in Florida. A 2020 investigation found that more than 900 state and local government workers had abused DAVID access to look up ex-partners and public figures, prompting the state to pass House Bill 1541 in 2021 to mandate enhanced database training and tougher penalties, according to WTSP 10 Investigates.

The DMV incident also follows a string of recent cyberattacks against Florida government entities, including breaches targeting the City of Pensacola in March 2024 and the Florida Department of Health in July 2024, Tampa Bay 28 notes. For now, key questions remain unanswered: how many Florida drivers were ultimately affected, whether Plant City police or FLHSMV will face civil claims under the Driver's Privacy Protection Act, and what discipline, if any, the Plant City employee may face. FLHSMV has said only that it will release additional information at an appropriate time in the future.

Tampa-Crime & Emergencies