The breach came through a single Plant City Police Department user's credentials stored on a personal device
Assessment
This is the state's own finding, stated in its 11 September release: "a criminal actor was able to take advantage of a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device." It is verified as the entry vector FLHSMV identified. It does not establish that the credential was the only account used, how the device was compromised, or whether the user was sworn or civilian; Plant City PD has not commented, and FLHSMV has not addressed the attacker's claim of subsequent account compromises.
Where this claim appeared
FLHSMV via BleepingComputer · 2026-09-11
https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/What “Verified” means
Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.
5 of 5 · rating scale
Assessed in
Florida DAVID Breach: One Officer's Stored Password, 200,000 Driver Records, and a Database With a HistoryThink this assessment is wrong? Report an error.