THE BRIEFWhat happened
Florida’s Department of Highway Safety and Motor Vehicles has confirmed that its DAVID driver database was breached after attackers used credentials belonging to an employee of a police department. Independent reporting reflects the state’s confirmation and the credential-based access path.
The available information does not establish how long the account was usable, exactly what records were accessed, or whether all claims about the incident’s scale are accurate. That distinction matters: a confirmed intrusion is not the same as a confirmed wholesale extraction of the database.
Organizations that connect to, query, or rely on driver-record systems should treat the event as a warning about trusted third-party access. The immediate concern is not only the stolen account itself, but also whether its permissions, authentication controls, monitoring, and downstream data access were appropriately limited.
Public agencies should review access involving law-enforcement partners and other external users, while affected individuals should rely on official notices for confirmed information rather than speculation about exposed records.