A hacking group known as ShinyHunters breached Florida’s DAVID driver and vehicle database last week, and the entry point was simpler than you might expect. According to FLHSMV, a Plant City Police Department employee had login credentials stored on a personal device. When that device was compromised, the credentials gave hackers access to the state system. The group claims it stole roughly 200,000 driver licenses and demanded a ransom to delete the data. The ransom deadline passed Friday with no public update on whether the state will pay.
Cybersecurity experts call this “shadow IT,” the practice of work credentials and tools living on personal devices where they aren’t protected by an agency’s security systems. For Suncoast residents, the takeaway is practical: a single unsecured phone or laptop can expose data belonging to hundreds of thousands of people. FLHSMV says it has notified the attorney general’s office and will alert affected Floridians directly.
If you hold a Florida driver license, watch for official notices and be wary of unexpected calls, texts, or emails asking you to confirm personal information. Scammers often piggyback on real breaches. Have you ever saved a work password on your personal phone? Tell us in the comments.



