← Back to Feed

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

September 11, 2026 · The Record · Severity: CRITICAL

Florida has confirmed that a motor vehicle data breach resulted from a credential-stuffing attack on a third-party contractor, using credentials stolen from an officer's personal device. The breach exposed driver license records and vehicle registration data, and the state is notifying affected residents while recommending credit monitoring.

Key Takeaways

  • Florida officials confirmed that a motor vehicle data breach was caused by a credential-stuffing attack on a third-party contractor using credentials stolen from an officer's personal device. This exposed driver license records and vehicle registration data. The incident underscores the risks of using personal devices for accessing sensitive government systems.
  • The breach resulted from attackers using credentials obtained from a personal device to access the contractor's systems via credential stuffing. This allowed unauthorized access to state motor vehicle databases, exposing personal identification information. Florida is now notifying affected residents and offering credit monitoring services.
  • This incident highlights the dangers of credential reuse and the need for robust access controls, including multi-factor authentication, for any account accessing sensitive data. The use of personal devices for work-related access to government systems creates significant security vulnerabilities. Organizations should enforce strict policies to separate personal and professional credentials.
☕ Buy a Coffee