An international criminal organization broke into a Florida state database using nothing more sophisticated than a police employee’s login credentials, which had been improperly stored on a personal device. State officials still won’t say how many drivers were affected, what information was taken, or who was responsible.
The Florida Department of Highway Safety and Motor Vehicles said in a statement released Friday that it learned of the breach on Sept. 4. In the ten days since, the agency has offered few specifics beyond confirming the intrusion happened and insisting it has been “quickly mitigated.”
According to FLHSMV’s own account, hackers gained access using login credentials belonging to a Plant City police employee — credentials that were, by the department’s own admission, improperly stored on a personal device rather than secured through the agency’s own systems. That detail alone raises a basic question state officials have not yet answered: how many other login credentials tied to Florida’s motor vehicle records sit similarly unprotected on personal devices across the state, waiting for the next criminal organization to find them?
The department called the perpetrators an “international criminal organization” without naming the group, and has not disclosed how many Florida drivers’ personal information may have been exposed or what categories of data — license numbers, addresses, dates of birth — were accessed. FLHSMV said it is now working with the Florida Digital Service and the Florida Department of Law Enforcement, but framed the lack of detail as a function of an ongoing criminal investigation.
“As this is an ongoing criminal investigation, further information will be released at an appropriate time in the future,” the agency said.
That may be true as far as the criminal probe goes. But Florida drivers whose personal information sits in FLHSMV’s databases are entitled to know, sooner rather than later, whether their own records were among those exposed — not on the state’s preferred timeline, but on a timeline that lets them protect themselves. An agency that holds sensitive personal data on millions of Floridians owes the public more than a one-paragraph statement and a promise to say more “at an appropriate time.”
The breach is also a reminder that data security failures rarely start with a sophisticated foreign hack of a hardened system. They start with basic lapses — a password saved somewhere it shouldn’t be, an access control that wasn’t enforced — that turn an ordinary government database into a soft target for organized criminal groups operating from outside U.S. jurisdiction. Whatever else comes out of the investigation, that underlying failure in how the state protects the credentials guarding Floridians’ personal information deserves scrutiny of its own, separate from whoever ultimately gets blamed on the other end of the breach.
FLHSMV has not said whether the Plant City Police Department has taken any action regarding the employee whose credentials were used, and did not respond to questions about broader password-security policies across agencies with access to its systems.
Follow the St. Pete-Clearwater Sun on Facebook, Google, & X
St. Pete-Clearwater Sun: local St. Pete-Clearwater & Tampa Bay, FL news at PIE-Sun.com
Dad. Father. Author.
S4: Students, Schools, Social Media, & Success, and The College Merit Scholarship Appeal Guide
Owen has also contributed to The Houston Chronicle, San Francisco Gate, AOL, BAM Magazine, Boss Magazine, and Tampa Bay Business Insider.
Leave a Reply