Need IT help now? Call (321) 221-7117 — We respond within 2 hours.

Need IT help? Help Desk Request Assistance Get in Touch
Cybersecurity

The Florida DMV Data Breach Started With One Saved Password

Oct 8, 2026·5 min read·By Ric Acevedo

What happened in the Florida DMV data breach?

In September 2026, attackers got into DAVID, the Florida driver and vehicle database police use to look up drivers. The state says they did it with one login belonging to a Plant City Police Department user, which had been saved on that employee’s personal device. The group behind it claims it took over 200,000 driver records. For a small business, the lesson is about saved passwords, not police databases.

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) says it learned of the breach on September 4, shut off the access, and has seen no further unauthorized activity. It reported the incident to the Florida Attorney General and is working with the Florida Department of Law Enforcement and the Florida Digital Service, according to BleepingComputer.

The extortion group ShinyHunters claimed responsibility and says it stole records including names, addresses, dates of birth, driver’s license numbers and Social Security numbers. The state has not confirmed that number, and the group’s own account differs: it claims it used a flaw in the password reset process to take over several accounts. The state’s investigation points to the single saved login. Either way, the way in was an account, not a hack of the database itself.

How can one saved password expose 200,000 records?

Because a login does not know who is typing it. DAVID is used by law enforcement agencies across Florida to look up driver records. Whoever holds a working username and password, and gets past any second check, looks exactly like the officer it belongs to.

Passwords saved on personal phones and home computers are one of the most common ways those logins leak. The usual routes are:

  • Information-stealing malware on a home PC or phone, often from a pirated app, a game mod or a fake browser update. It quietly copies every password saved in the browser and sends them to the attacker.
  • A synced personal account. If work passwords are saved in a personal Google or Apple account, anyone who gets into that account gets all of them.
  • Notes and photos. Passwords typed into a notes app or a photo of a sticky note get backed up to personal cloud storage nobody at the business controls.

None of these involve the employee doing anything malicious. They saved a password to make their job easier, on a device the employer had no visibility into.

Does this happen to small businesses too?

Yes, and it is one of the most common ways small business email accounts get taken over: a staff member’s password is saved on a personal device, the device gets infected or the personal account is compromised, and weeks later someone is logged into the work mailbox sending fake invoices to customers.

The difference is scale. A police login opens a statewide database. A front desk login at a medical practice opens patient records; a bookkeeper’s login opens the bank portal and every client’s tax documents. For a small business, the one leaked password is the breach. And under Florida law, a breach involving 500 or more people has to be reported to the state as well as to the people affected, within 30 days.

What should a business do about passwords on personal devices?

You do not have to ban personal phones. You do have to decide what they are allowed to hold. Five changes cover most of the risk:

  1. Turn on multi-factor authentication everywhere it exists: email, Microsoft 365 or Google Workspace, banking, payroll, your EHR or practice software, and remote access. A stolen password with MFA in front of it is usually useless. Prefer an authenticator app or a security key over text messages; CISA’s guidance explains why.
  2. Give staff a business password manager instead of letting them save work passwords in personal browsers. The business owns it, and when someone leaves, their access goes with one click.
  3. Write a short personal-device policy: which work apps are allowed on a personal phone, that work passwords are never saved in a personal account, and what happens if the phone is lost. We wrote a version for medical offices in our BYOD guide, and most of it applies to any business.
  4. Use one account per person, never shared logins. When something goes wrong you need to know whose account it was and shut off just that one.
  5. Check whether your passwords have already leaked. Our free password breach check tells you in seconds whether a password appears in known breach data, without the password ever leaving your browser.

Was my information exposed in the DMV breach?

The state has not published a list of affected people, and the 200,000 figure comes from the attackers, not FLHSMV. If you hold a Florida license, the sensible steps are the same ones that apply after any large breach: check your credit reports for free, consider a credit freeze with all three bureaus, turn on MFA on your email, check that nobody can send email pretending to be your business, and treat any call or email “about the DMV breach” with suspicion, because scammers use these headlines. Only trust notices you can verify on flhsmv.gov. If you do find signs of identity theft, the FTC’s IdentityTheft.gov walks you through the recovery steps.

Want to Know What Your Team’s Devices Are Holding?

iTech Plus provides cybersecurity and managed IT for small businesses and medical practices across Polk County and the surrounding area, including Lakeland, Plant City, Winter Haven and Davenport. We turn on MFA, set up business password managers and write personal-device policies people actually follow. For the basics, see cybersecurity for small businesses, or ask for a free IT assessment with a written report. Call (321) 221-7117 or email info@itechplus.co.

Recent Articles

Cybersecurity Services in Kissimmee, FL: Protecting Vacation Rentals, Practices and Small Businesses
Cybersecurity
Cybersecurity Services in Kissimmee, FL: Protecting Vacation Rentals, Practices and Small Businesses
Oct 9, 2026
State of Email Security in Polk County 2026: 63% of Businesses Can Be Impersonated
Cybersecurity
State of Email Security in Polk County 2026: 63% of Businesses Can Be Impersonated
Oct 9, 2026
Cybersecurity Services in Winter Haven, FL: What Local Businesses Need
Cybersecurity
Cybersecurity Services in Winter Haven, FL: What Local Businesses Need
Oct 8, 2026
What to Ask Before Hiring a Ransomware Recovery Company
Cybersecurity
What to Ask Before Hiring a Ransomware Recovery Company
Oct 8, 2026
Cybersecurity Services in Lakeland, FL: What Local Businesses Actually Need
Cybersecurity
Cybersecurity Services in Lakeland, FL: What Local Businesses Actually Need
Oct 6, 2026

Related posts

Digital Business Card