Executive Summary

In September 2026, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed that its DAVID driver database was breached by the ShinyHunters extortion group, who claimed to have stolen over 200,000 driver records. The attack was executed using compromised credentials from a Plant City Police Department employee that had been improperly stored on a personal device. The breach was discovered on September 4, 2026, and quickly mitigated, with FLHSMV working alongside state law enforcement agencies in their response. This incident highlights the growing trend of cybercriminals targeting government databases through compromised credentials and the critical importance of proper credential management across interconnected systems.

Why This Matters Now

This breach exemplifies the escalating threat to government databases from credential-based attacks, particularly as threat actors increasingly exploit weak credential storage practices to access sensitive citizen data across interconnected public safety systems.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attackers used compromised credentials from a Plant City Police Department employee that had been improperly stored on a personal electronic device to access the DAVID database.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained ShinyHunters' lateral movement through the DAVID DMV system by enforcing segmented access between database components and police department credentials. The attack's blast radius would likely have been reduced through workload isolation and controlled east-west traffic enforcement.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Application-level segmentation would likely have limited the scope of initial access by isolating the password reset functionality from core database operations and restricting credential reuse across system boundaries.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware segmentation would likely have constrained privilege escalation by enforcing role-based access boundaries between police department credentials and DMV employee accounts, limiting cross-jurisdictional access paths.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation enforcement would likely have constrained lateral movement between database segments and user accounts, reducing the attacker's ability to traverse across jurisdictional boundaries within the DAVID infrastructure.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility and policy enforcement would likely have detected and constrained the systematic record ID iteration patterns, limiting the attacker's ability to maintain persistent automated access across database segments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress policy controls would likely have constrained the systematic downloading of large volumes of driver records by limiting outbound data transfer rates and restricting bulk extraction patterns from database systems.

Impact (Mitigations)

While sensitive driver information would still require breach notification and remediation, the scope of exposed records would likely have been significantly reduced through segmented database access and constrained lateral movement capabilities.

Impact at a Glance

Affected Business Functions

  • Driver License Services
  • Vehicle Registration Systems
  • Law Enforcement Database Access
  • Motor Vehicle Records Management
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Over 200,000 driver records containing sensitive personal information including driver's license data, vehicle registration information, addresses, and potentially other PII. The breach exposed records accessible through the DAVID database system used by DMV employees and law enforcement agencies.

Recommended Actions

  • Implement Zero Trust Segmentation to limit database access based on identity and role, preventing lateral movement between user accounts
  • Deploy Egress Security & Policy Enforcement to detect and block systematic data extraction attempts and unauthorized outbound transfers
  • Enable Multicloud Visibility & Control to monitor anomalous database query patterns and repeated access to sensitive records
  • Strengthen Encrypted Traffic (HPE) controls to protect data in transit during database queries and prevent credential interception
  • Implement Threat Detection & Anomaly Response to baseline normal database access patterns and alert on suspicious credential usage from personal devices

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image