Florida says one police department login let attackers download driver records.
The Florida Department of Highway Safety and Motor Vehicles confirmed attackers accessed DAVID, the state's driver database, BleepingComputer reported.
Investigators found the intrusion used "compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee's personal electronic device".
ShinyHunters claims it downloaded more than 200,000 driver records. The department has not confirmed that figure and described the attackers as "an international cybercriminal organization".
The downloads began on 3 September. The department detected them the next day and disclosed the breach publicly on 11 September, saying it "was quickly mitigated and no further breach has occurred or is ongoing".
Its account identifies no software vulnerability. One valid partner login was enough.
Which ERP accounts belong to partners, and whose device rules apply to them?
Sources
Every story here is open to read. The ERP LEADERS brief goes one step further.
One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.
Welcome back. · Issue 01
