FLHSMV Confirms Incident Linked to Police User Account

Florida’s transportation agency confirmed unauthorized access linked to the credentials of a Plant City Police Department user. It has not yet disclosed the scope of the affected data.

A security incident was confirmed by Florida’s Department of Highway Safety and Motor Vehicles (FLHSMV). The agency said it learned of the breach on September 4, 2026. According to its investigation, an attacker misused the credentials of a single user from the Plant City Police Department, which had been improperly stored on an employee’s personal electronic device.

FLHSMV publicly confirmed the incident on September 11. The agency described the organization behind the attack as an international cybercrime group but did not name it.

What the FLHSMV Security Incident Confirms

According to FLHSMV’s statement, the breach involved access associated with a Plant City police department user account. The user’s credentials had been improperly stored on an employee’s personal device.

FLHSMV said it quickly mitigated the incident and that no further breach was occurring. The agency also reported the event to Florida’s attorney general. It is cooperating on the investigation with Florida Digital Service and the Florida Department of Law Enforcement.

Scope of Possible Data Leak Remains Unknown

The official statement does not specify which system was involved in the incident. FLHSMV also did not disclose the number of records accessed, the types of personal information that may have been affected, or the number of potentially impacted people.

It is therefore not possible to confirm the impact on specific drivers or determine what data may have been accessible through the compromised account. The agency also did not say whether it would notify individuals who may have been affected.

The group calling itself ShinyHunters publicly claimed responsibility for the attack, but FLHSMV has not officially confirmed its responsibility. Claims of more than 200,000 stolen records and an alleged exploitation of a password-reset flaw also remain unverified.

Risk of Accounts Across Institutions

The case concerns access to a state transportation agency’s systems through a user account from another public institution. The confirmed circumstances point to risks associated with storing credentials on personal devices, especially for accounts with access to sensitive government data.

FLHSMV has not yet disclosed details about remediation measures for accounts used by law enforcement agencies. It also remains an open question whether investigators will confirm or rule out a connection between the incident and the ShinyHunters group.

Further information should clarify the scope of the incident, the type of affected data, the number of impacted people, and any notifications to individuals whose information may have been accessed.

Sources

  • Florida Department of Highway Safety and Motor Vehicles – FLHSMV’s official statement confirms the incident, the date it was discovered, misuse of a Plant City Police Department user account, storage of the credentials on a personal device, and the mitigation status.
  • The Record – Corroborates the timing of the confirmation’s publication and reports an earlier public claim by the ShinyHunters group, which remains unofficial.

Verified and updated: 09/12/2026 15:22

Sharing