One officer's phone, one saved password, one state driver database
Florida's Department of Highway Safety and Motor Vehicles confirmed on 11 September what an extortion crew had been claiming for a week. DAVID, the system police and state agencies use to pull up driver records, vehicle details and the personal information attached to them, was broken into. The agency says it learned of the intrusion on 4 September, the day after the downloading started, and that the access has since been closed.
The way in is the part worth reading twice. The investigation found the attacker used the credentials of one Plant City Police Department user, and that those credentials had been, in the agency's own phrasing, improperly stored on the employee's personal electronic device. One person keeping a work login somewhere convenient. That is the entire chain.
ShinyHunters, who claimed the attack, say they took more than 200,000 driver records. Florida has not confirmed a figure and has not said which fields were exposed, though the group's proof-of-access screenshot showed a DAVID record containing a licence number and a Social Security number. The Florida listing then vanished from the group's leak site on the same day the state went public, which people who watch these crews tend to read as a sign that a conversation took place. It is also the second haul of American driver's licence data to surface this month, after the IDScan breach that Brian Krebs reported on 3 September.
You cannot do anything about a password an officer in Florida saved on their phone. You can do something about the same habit on your own machine, which is more common than anyone admits: the text file of logins sitting on the Desktop, the browser signed into a bank on a PC with no lock screen. Tendvane's privacy and accounts check shows which accounts your PC is signed into and how each one is protected, and it is usually a longer list than people expect.