Skip to main content

September 21, 2026

The Florida DMV Breach Is a Warning for Orlando Businesses

One set of stolen credentials opened Florida's driver database. What the DAVID breach means for Orlando businesses and how to tighten your own logins.

A police login, a personal device, and every Florida driver

On September 4, Florida’s Department of Highway Safety and Motor Vehicles discovered that someone had been inside DAVID, the Driver and Vehicle Information Database that law enforcement and authorized agencies use to look up driver and vehicle records. The state says the incident was contained quickly and that there is no ongoing breach. Less than two weeks later, the hacking group ShinyHunters published stolen data from it anyway, according to TechCrunch’s September 16 report.

The entry point was not a zero day or some exotic exploit chain. Per CBS12’s reporting, the attackers used credentials belonging to a Plant City Police Department user, and the state found those credentials “had been improperly stored on a personal electronic device.”

One saved login. That was the whole door.

ShinyHunters claims more than 200,000 Florida driver records were taken. The state has not confirmed that number, and it may never match what the attackers say. The group told TechCrunch it published the data because the victim “did not pay a ransom or cooperate and comply.” The Florida Attorney General’s Office, the Florida Digital Service, and FDLE are all investigating, and FLHSMV has not yet said whether affected drivers will be notified.

What actually got published

Based on TechCrunch’s review of the leaked files, the published data includes hundreds of thousands of vehicle ownership certificates carrying owner names, addresses, and vehicle identification numbers. A smaller subset contains Social Security numbers, non-US passports, and immigration documents. Driver’s license photos were not part of the dump.

That mix matters. Names, home addresses, and VINs are exactly the ingredients for convincing pretext calls and letters. A caller who can read your plate, your VIN, and your home address off a screen does not sound like a scammer. They sound like your insurance company, your lienholder, or a DMV clerk.

Stuck on something like this right now?

Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.

Book a Free Strategy Session

Why Orlando businesses should treat this as their problem

DAVID holds records on essentially every licensed driver in Florida. If you run a business in Orlando, some slice of your employees, your customers, and probably you are plausibly in the exposed pool. Nobody knows the full scope yet, and that uncertainty is the point. You cannot wait for a notification letter that may not come.

The near-term risk for a business is not identity theft in the abstract. It is targeted social engineering built on accurate personal details. Expect phishing emails and phone calls that reference real vehicles, real addresses, and real names, aimed at payroll changes, wire transfers, and password resets. The person approving invoices at a twelve-person company in Winter Park gets the same quality of bait as a Fortune 500 treasury team, with far less process standing behind them.

There is a second lesson here, and it is the uncomfortable one. The state of Florida runs security programs most small businesses could not afford, and it still got beaten by a login stored where it should not have been. Your company has the same failure mode. Somewhere on a personal phone, a home laptop, or a text thread, one of your people has stashed a work password. Attackers do not need to beat your firewall if they can find that.

The fixes are boring, which is why they work

None of what follows requires new hardware or a security budget line that makes you wince. It requires deciding that credentials are infrastructure.

Put every work password in a managed password vault and make it the only sanctioned place credentials live. If passwords are in browsers on personal devices, in spreadsheets, or on sticky notes, the vault has not actually been adopted, just purchased.

Turn on phishing-resistant MFA for email, VPN, and any system that touches money or customer data. App-based prompts are good. Hardware keys or passkeys are better, because the ShinyHunters playbook leans hard on tricking people into approving logins.

Write down which third-party systems your staff can log into, from vendor portals to state databases to your line-of-business apps, and cut every account that is not needed. The Plant City lesson is that your risk includes every external system your credentials can open, not just your own network.

Set a real rule for personal devices. Either a device is enrolled and managed, or it does not hold work credentials. A polite policy PDF nobody follows is not a control.

Verify callers before resets. Attackers holding leaked personal data are very good on the phone. At Cyber Command we use double-blind user verification, where both sides confirm identity through a separate pre-agreed channel before any password reset or remote session happens. It is designed to stop exactly the kind of impersonation this leak makes easier. If your current IT support will reset a password for anyone who sounds confident and knows the boss’s home address, this breach just made that gap wider.

And assume some credentials tied to your domain are already circulating. Monitoring for stolen-credential reuse is a standard part of managed cybersecurity work now, not an enterprise luxury.

If you think you have a problem right now

Move fast and keep it simple. Reset the affected account, kill its active sessions, and check what that login could reach. Then look at mail rules, forwarding, and recent payment changes, because that is where credential thieves go first. If any of that turns up something odd, get help before you start deleting evidence. This is standard incident response services territory, and the first hours matter more than the tools.

For Orlando companies without a security team on staff, this is the week to have a direct conversation with whoever handles your IT. Ask three questions. Where do our passwords actually live? Who can reset them, and how do they verify the request? What outside systems can our accounts open? If the answers are vague, that is your finding.

Cyber Command provides managed IT services in Orlando and across Tampa Bay and Jacksonville, with a US-based team that answers 24/7. No phone trees, no ticket black holes. Our business IT services and human-managed SOC are built to reduce the risk that one stashed password becomes your whole story. If you want a second set of eyes on your credential hygiene before the pretext calls start, talk to a real expert or call (407) 587-0089.

#CyberSecurity #ManagedIT #DataBreach #Orlando #CentralFlorida

This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.