TALLAHASSEE, FL — Florida highway safety officials say an international cybercriminal group gained access to data by exploiting login credentials tied to a Plant City police employee. The credentials were stored improperly on the employee’s personal electronic device, according to the Florida Highway Safety and Motor Vehicles Department.
The department said it learned of the breach on Sept. 4, 2026, and moved quickly to contain it. Officials said no further breach has occurred and that the incident is not ongoing. The agency has not said what information was accessed, but it described the event as a data breach that triggered a formal state notice.
How the credentials were allegedly exposed
Investigators determined that a criminal actor took advantage of a single user’s credentials from the Plant City Police Department, the department said. Those login details were improperly housed on the employee’s personal device, creating the opening that allowed access.
The state agency did not identify the employee or say how long the credentials were stored that way. It also did not say whether the compromised information belonged only to the police department or whether it extended further into state systems. What officials did stress is that the breach was tied to one set of credentials rather than a broader system failure.
State notice filed with the attorney general
Florida Highway Safety and Motor Vehicles said it gave the required breach notice to the Office of the Attorney General under section 501.171 of the Florida Statutes. That law sets out notification steps for security breaches involving sensitive information.
The department did not release the text of the notice, but said it followed the required reporting process after the incident was discovered. The announcement suggests the breach was handled as a statutory disclosure issue as well as a security event, which is standard when state agencies determine that unauthorized access has occurred.
Florida Digital Service and FDLE join the response
The highway safety department said it is working with the Florida Digital Service and the Florida Department of Law Enforcement as part of its response. Those agencies are involved in helping assess the incident and support the investigation.
Officials said the breach has been mitigated, but they offered no further technical details about the response steps. They also did not say whether any passwords were reset, whether the employee’s device was recovered or secured, or whether additional monitoring has been put in place. The main message from the agency was that the incident was quickly brought under control.
Why the case stays under criminal investigation
The department said the matter remains an ongoing criminal investigation, which is why officials are limiting what they can say publicly for now. Because of that, they said additional information will be released at an appropriate time in the future.
That leaves key questions unanswered, including the identity of the cybercriminal organization and the scope of the data accessed. For now, the state’s message is that the unauthorized access has been contained, the required breach notice has been filed, and law enforcement partners are continuing to examine how the credentials were misused.
What the breach means for Plant City and state systems
The incident centers on a local police employee’s credentials, but it reached a state agency that handles driver and vehicle records and other public-safety functions. Florida Highway Safety and Motor Vehicles said the breach was discovered and addressed, which suggests the risk of continuing exposure was limited.
Even so, the episode highlights how a single set of improperly stored login credentials can create broader security problems. State officials have not described any public impact to services, and they have not said that the breach is still affecting operations. For now, the confirmed facts are limited to the access event, the required notice, and the multi-agency response.
