BriefPulse Security · Security reporting tied to advisories, affected versions and action. RSS · BriefPulse network
BriefPulse Security

Exposures, incidents and defensive changes for people who have to act.

16 September 2026

Brief

Florida DMV confirms breach tied to credentials on officer's personal device

The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it began with credentials stolen from a police officer's personal device.

The Florida Department of Motor Vehicles has confirmed a data breach claimed by the cybercrime group ShinyHunters. The Record reports the incident originated with credentials stolen from a police officer's personal device.

For small teams, the case shows how credentials kept on a personal phone or laptop can expose an organisation's systems when the device is lost. The report gives the origin of the breach, not a count of affected people or records.

Our reading

Our reading is that credentials stored on personal devices are a practical weak point for small teams, and that MFA and device encryption are worth switching on before an incident rather than after one.

What to do or watch

Watch for follow-up reporting from Florida DMV or The Record that states how many people or records were affected, since the confirmed details so far cover only the breach's origin. In the meantime, small teams can check whether work credentials are stored on employees' personal phones or laptops, which is the weak point this incident points to.

Source details and supporting facts

Each line is stated by the page named above it.

Stated by The Record

  • The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters.
  • The breach originated with the theft of credentials stored on a police officer's personal device.

Sources

  1. The RecordText stored 14 September 2026

How this story was checked. Written from the 1 page listed above, stored 14 September 2026; claims checked against that stored text on 14 September 2026.

What that means
  • 2 of 2 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
  • Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
  • The check reads stored text only: no claim rests on a fresh look that did not happen.
  • Where the reporting was silent, the text says so instead of filling the gap.

More from Security