Skip to content

Enterprise software, read for what it costs and who signs for it.

Software business

Florida says one police department login let attackers download driver records.

The Florida Department of Highway Safety and Motor Vehicles confirmed attackers accessed DAVID, the state's driver database, BleepingComputer reported.

ERP LEADERS news desk · · First reported by BleepingComputer · Edition no. 6
Photo: The Bushranger/Wikimedia, CC BY-SA 4.0 · original

Investigators found the intrusion used "compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee's personal electronic device".

ShinyHunters claims it downloaded more than 200,000 driver records. The department has not confirmed that figure and described the attackers as "an international cybercriminal organization".

The downloads began on 3 September. The department detected them the next day and disclosed the breach publicly on 11 September, saying it "was quickly mitigated and no further breach has occurred or is ongoing".

Its account identifies no software vulnerability. One valid partner login was enough.

Which ERP accounts belong to partners, and whose device rules apply to them?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story
Florida Department of Highway Safety and Motor Vehicles

Every story here is open to read. The ERP LEADERS brief goes one step further.

One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01