/

September 17, 2026

Florida Confirmed the DMV Breach — and the Hackers’ Story About How They Got In Was Wrong

Last week we wrote about an extortion group’s claim that it had broken into Florida’s driver database, and we spent most of that article separating what was actually confirmed from what was merely being asserted by people who profit from being believed. We said the sensible posture was to take cheap precautions without panicking, and that if the state confirmed, the advice wouldn’t change — it would just become urgent.

Florida has now confirmed it. And the most important thing to come out of that confirmation isn’t the breach itself. It’s that the hackers’ account of how they got in appears to have been wrong — and the real answer is far more relevant to your business than the one they were selling.

They claimed they had found a flaw in the system. The state’s investigation says there was no flaw. There was one stolen login, belonging to a police officer at a completely different agency, that had been improperly stored on that person’s own phone. That’s it. That’s how the most sensitive database in the state got opened.

Let’s go through what’s confirmed, what’s still unknown, why the correction matters for how you read every breach story from here on, and the lesson underneath it — which is one we’ve written about before and which just got the clearest illustration it’s ever going to get.

What’s changed since last week

Here’s the same ledger we ran last time, updated. If you read the original article, this is what moved:

What we said a week agoWhere it stands now
The group claims it breached DAVID, Florida’s law-enforcement driver databaseConfirmed. The state’s motor vehicle agency says it learned of a data breach on September 4 and described it as conducted by an international cybercriminal organization.
It claims it got in through a password-reset flaw, taking over DMV and FBI accountsContradicted. The agency’s investigation found the attacker used compromised credentials belonging to a single police department user — credentials that had been improperly stored on that employee’s personal device. The official account makes no mention of a system-wide flaw.
It claims more than 200,000 driver recordsStill unconfirmed. The state has not confirmed that figure or released any count of its own. That number remains the claim of the people who took the data.
It set a deadline of September 11 to publishThe state’s confirmation landed on September 11 — the same day as the deadline. The agency says it notified the Attorney General’s office as state law requires and is working with state law enforcement and the state’s digital service.
Sample record posted as proofStill unverified. The authenticity of the posted sample has not been confirmed by the state.

Two additional details from the agency’s statement are worth having. It says the breach was quickly mitigated and that no further breach has occurred or is ongoing. And notably, reporting indicates the agency’s own security team detected the unauthorized activity on September 4 — independent of, and days before, the group went public with its listing. We’ll come back to that, because it’s the part of this story where somebody did something right.

The correction that matters: attackers narrate, they don’t testify

Look carefully at the second row of that table, because it’s the most instructive thing in this entire story.

For roughly a week, the dominant version of this story — carried in headline after headline — was that a password-reset vulnerability in a state system had allowed criminals to hijack accounts including one belonging to a federal agent. That’s a dramatic narrative. It suggests a broken system, a technical failure at the state level, a flaw that might still be out there. It’s also, according to the state’s investigation, not what happened.

Why would the attackers describe it differently? We don’t know, and it’s worth being careful here — it’s possible they misrepresented it deliberately to sound more capable than they were, possible they were describing something real that the state’s account simply doesn’t address, and possible the full picture is more complicated than either version. Investigations are ongoing. But the general principle stands regardless of which is true in this case, and it’s one worth internalizing:

An attacker’s explanation of how they got in is a marketing claim, not a finding. Extortion groups have every reason to sound sophisticated — it raises their profile, it makes the victim feel helpless, and “we defeated their system” pressures a payment far better than “somebody left a password on their phone.” Their numbers, their methods, and their proof are all part of a sales pitch aimed at getting paid. This is exactly why we hedged so heavily last week, and it’s why we’d hedge again: when the only source for a detail is the criminal, that detail is not yet a fact. It’s an assertion, and assertions get corrected.

What actually happened: one login, on one personal device, at another organization

Now to the real cause, and it deserves to be stated as plainly as possible, because the plainness is the point.

Florida’s driver database is a restricted system. You’ve never logged into it. It exists so that police officers and other authorized officials can look up driver and vehicle records — the tool used during a traffic stop. Access to it is a privilege extended to law enforcement agencies across the state.

According to the investigation, the credentials of one user at one police department — a city department, not the state agency — had been improperly stored on that employee’s personal electronic device. Those credentials were compromised, and someone used them to log into the state’s database and start pulling records. The system didn’t fail. Its defenses weren’t beaten. Someone simply walked in the front door with a real key that had been left in a place it should never have been.

Sit with the asymmetry in that for a moment. The state can invest enormous sums in securing that database — hardening it, monitoring it, auditing it, architecting it properly. None of that investment does anything whatsoever about a password sitting in a notes app on a personal phone in another city, at an organization the state doesn’t run, belonging to an employee it doesn’t manage. Every dollar spent on the vault is irrelevant when the key is outside the building.

Where we’ve seen this exact shape before

Regular readers will recognize this, because we wrote about the identical pattern in a completely different context not long ago. When attackers shut down a turbine at a power plant in Poland, they didn’t break into the power plant. They broke into a wind farm — a separate company, miles away — and crossed into the plant through a shared connection that neither facility controlled. We called that lesson trusted connections: your security is only as strong as the things you’re connected to, including the ones you don’t control and can’t see.

This is the same story wearing different clothes. A state database was reached through a city police department. A power plant was reached through a wind farm. In both cases the target’s own defenses were beside the point, because the attacker never had to go through them. They went around, through a partner.

And there’s a version of this sitting in nearly every business, including yours.

Your real perimeter is every person who holds a login

Here’s the translation for a small business, and it’s uncomfortable in a useful way. Think about everyone who currently has a login to something of yours:

  • Your bookkeeper or accountant, who has access to your financial system from their own office, on their own computer, under their own security practices — which you have never seen.
  • Your web person or marketing contractor, who has admin access to your website and probably your social accounts.
  • Vendors with remote access to service your equipment, your point-of-sale, your building systems.
  • A former employee whose account nobody ever disabled, on a device you no longer control.
  • Your current employees’ personal phones, which are almost certainly signed into work email, and which may well have work passwords saved in a browser, a notes app, or a text message they sent themselves.

Every one of those is a key to your business that lives somewhere you don’t administer, protected by habits you didn’t set and can’t inspect. That’s not a reason for paranoia about the people you work with — the police officer in this story almost certainly did not intend to hand anyone the keys to a state database. It’s a reason to recognize that your security perimeter is not your office and it is not your network. It is the set of all people who hold a credential to something of yours, plus every device those credentials touch. That perimeter is much larger than most owners picture, and most of it is outside the building.

The single control that would have blunted this

Here’s the practical center of the whole story. A stolen password, by itself, opened a state database.

That is the scenario multi-factor authentication exists to defeat. When a second verification step is required, a stolen password is an incomplete key — the attacker has half of what they need and no way to get the other half. We don’t know the full authentication picture on the account involved here, and we’re not going to speculate about it. But the general lesson is not speculative at all, and it applies directly to you: anywhere in your business where a password alone is enough to get in, you have recreated the exact conditions of this breach.

So here’s the short, concrete list. None of it is exotic and all of it is doable:

  1. Multi-factor authentication on everything that matters — email first, then financial systems, then your website and any system holding customer data. This is the control that turns a stolen password from a disaster into a nuisance.
  2. Get work credentials off personal devices and out of insecure places. Passwords in a phone’s notes app, in a browser on a personal laptop, on a sticky note, in a spreadsheet, in a text someone sent themselves — all of it is the same failure with different packaging. A proper password manager solves this, and it’s one of the cheapest, highest-value tools a small business can adopt.
  3. Make a list of everyone outside your company who has a login to your systems. Most owners have never done this and are surprised by the length of the list. You cannot manage access you haven’t inventoried.
  4. Close accounts the moment they’re no longer needed. Departed employees, finished contractors, a vendor you stopped using two years ago. Every unused credential is a key in circulation with nobody watching it.
  5. Give people only the access their job requires. If the bookkeeper’s login can only reach the bookkeeping system, a compromise of that login is contained. Broad access turns one stolen password into a whole-business event.
  6. Ask your partners and vendors what their practices are. You’re inheriting their security whether you’ve asked or not. A short, friendly conversation about how they store the credentials you gave them is entirely reasonable.

Worth asking about your own business: Could you list, right now, every person outside your company who holds a login to one of your systems? * Is there anywhere in your business where a password alone is enough to get in? * Do you know whether your employees have work passwords saved on their personal phones? * And when someone stops working with you, is there a step that actually removes their access — or does it just quietly stay live?

Credit where it’s due — and what’s still unknown

Two things deserve a fair hearing here, because we try not to write one-sided posts.

First, the detection appears to have been good. Reporting indicates the agency’s own security team caught the unauthorized activity on September 4 — days before the extortion group posted its listing publicly. That matters. Compare it to the ransomware attack on Berlin’s government network we covered recently, where reporting described roughly a week between the first internal warning sign and the network actually being isolated. Catching an intrusion yourself, quickly, before the criminals announce it, is the thing most organizations fail at. Somebody there was watching, and that’s worth saying out loud.

Second, a real amount remains unknown, and we’re not going to paper over it. The state has not confirmed how many records were accessed. It has not publicly detailed exactly what categories of information were involved — reporters have asked specifically about sensitive categories and haven’t received substantive answers. And how affected individuals will be identified and notified isn’t yet clear. There’s also a fair debate happening about the seven days between internal discovery and public confirmation: relative to government disclosure generally that’s quick, and relative to what private companies are increasingly expected to do it’s less impressive. Reasonable people can hold both thoughts.

One more piece of perspective worth offering, because the coverage has been comparing numbers in a way that misleads. Set against the identity-verification exposure we covered earlier this month — the one involving scans of a reported 153 million licenses — a figure of 200,000 sounds small. But scale is the wrong lens. Those were scan events, many of them repeat visits by the same person. These are records: one per human being, with a name already joined to an address, a date of birth, a license number, and in the sample that was posted, a Social Security number. Two hundred thousand complete identities can do more damage per person than a far larger pile of partial ones. Don’t let a smaller headline number make this feel less serious if you’re one of the people in it.

If you’re a Florida driver

The advice from last week hasn’t changed — it’s just no longer precautionary. The breach is confirmed, the scope isn’t public, and there’s still no way to look yourself up, so the reasonable assumption is that you could be affected:

  • Freeze your credit at all three bureaus if you haven’t. Free, no effect on your score, liftable any time, and it blocks the main thing a complete identity record enables.
  • Expect impersonation attempts and refuse them. Now that this is confirmed and in the news, scam messages referencing it will follow — fake “DMV compliance” calls, texts about your registration, emails offering to check whether you were affected. There is no lookup tool. The DMV does not call, text, or email demanding payment or personal details through a link. Contact the agency yourself, through its official website.
  • Watch for new-account fraud and vehicle-related fraud — title, registration, and insurance schemes, along with the usual credit applications.
  • Turn on two-factor authentication on your email and financial accounts, so that identity details alone aren’t enough for someone to get in.

And if you’re outside Florida, don’t file this away as somebody else’s problem. Every state operates a system like this one, and the failure that caused this had nothing to do with Florida’s technology. It was a credential in the wrong place. That can happen anywhere, to anyone, at any organization that shares access with partners — which is all of them.

The takeaway

A week ago this was a claim, and we told you to treat the attackers’ version of events as unverified. The confirmation arrived, and the part they got most wrong was the part everyone had repeated the most: how they got in. There was no clever exploit. There was a real key, held by a trusted partner, stored somewhere it shouldn’t have been.

That’s the version of this story that should stay with you, because it’s the version that describes your business. You are not going to be breached by someone defeating your firewall. You are far more likely to be breached because a credential belonging to you, or to someone you trusted with access, ended up somewhere it shouldn’t be — on a personal phone, in a browser, in a note, in the hands of a contractor who left two years ago and whose account is somehow still active.

That’s exactly what our environment review is built to find. We inventory every account and every outside party with access to your systems, identify where a password alone is still enough to get in, find the credentials living in places they shouldn’t, and close the accounts nobody remembered were open. Florida’s database wasn’t beaten by a better attacker. It was opened with a key that was sitting in the wrong pocket. Let’s find out where your keys are before somebody else does.

Sources: Florida Department of Highway Safety and Motor Vehicles public statement (September 11, 2026); BleepingComputer; NBC News; Fox News; Florida Politics; CyberGuy; OODAloop; Rescana; and additional analysis published September 2026. The record count, the contents of the accessed data, and the authenticity of the sample posted by the extortion group remain unconfirmed by the state, and the criminal investigation is ongoing. Details attributed to the attackers are their own claims. This article is a follow-up to our earlier coverage published September 9, 2026.

From the same category