ThreatPaper
Verified

The breach came through a single Plant City Police Department user's credentials stored on a personal device

Assessment

This is the state's own finding, stated in its 11 September release: "a criminal actor was able to take advantage of a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device." It is verified as the entry vector FLHSMV identified. It does not establish that the credential was the only account used, how the device was compromised, or whether the user was sworn or civilian; Plant City PD has not commented, and FLHSMV has not addressed the attacker's claim of subsequent account compromises.

Where this claim appeared

FLHSMV via BleepingComputer · 2026-09-11

https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Florida DAVID Breach: One Officer's Stored Password, 200,000 Driver Records, and a Database With a History

Think this assessment is wrong? Report an error.