Brief
Florida DMV confirms breach tied to credentials on officer's personal device
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it began with credentials stolen from a police officer's personal device.
The Florida Department of Motor Vehicles has confirmed a data breach claimed by the cybercrime group ShinyHunters. The Record reports the incident originated with credentials stolen from a police officer's personal device.
For small teams, the case shows how credentials kept on a personal phone or laptop can expose an organisation's systems when the device is lost. The report gives the origin of the breach, not a count of affected people or records.
Our reading
Our reading is that credentials stored on personal devices are a practical weak point for small teams, and that MFA and device encryption are worth switching on before an incident rather than after one.
What to do or watch
Watch for follow-up reporting from Florida DMV or The Record that states how many people or records were affected, since the confirmed details so far cover only the breach's origin. In the meantime, small teams can check whether work credentials are stored on employees' personal phones or laptops, which is the weak point this incident points to.
Source details and supporting facts
Each line is stated by the page named above it.
Stated by The Record
- The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters.
- The breach originated with the theft of credentials stored on a police officer's personal device.
Sources
- The RecordText stored 14 September 2026
How this story was checked. Written from the 1 page listed above, stored 14 September 2026; claims checked against that stored text on 14 September 2026.
What that means
- 2 of 2 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
- Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
- The check reads stored text only: no claim rests on a fresh look that did not happen.
- Where the reporting was silent, the text says so instead of filling the gap.
More from Security
Report
Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warning
Brief
Google releases September 2026 patches for Pixel, fixing actively exploited zero-day
Brief