California DMV

California DMV Data Breach Allowed Social Security Information of Thousands to Be Improperly Accessed

The DMV, already besieged by other issues, says that 3,200 license holders had their data improperly exposed to federal agencies, including immigration authorities.

Facing problems ranging from long wait times to staffing and management issues, the California Department of Motor Vehicles announced Tuesday that it has also suffered a “data breach” that allowed federal agencies to improperly access Social Security information of 3,200 people in the state.

Immigration authorities were among the agencies who had access to the Social Security information, including if a person issued a license did not have a Social Security number, The Los Angeles Times reported. The information was disclosed through the Government Requested Code Account Program, which allows those agencies to access DMV information but only “for limited purposes under state and federal law,” according to CNN.

Seven agencies, including the Department of Homeland Security, the Internal Revenue Service and district attorneys in San Diego and Santa Clara Counties, accessed the information over the past four years.

After discovering the “breach” on Aug. 2, the DMV cut off access to the information. No hacking was involved, and private individuals were not given access to Social Security information, according to the DMV’s spokeswoman Anita Gore.

“Protection of personal information is important to DMV, and we have taken additional steps to correct this error, protect this information and reaffirm our serious commitment to protect the privacy rights of all license holders,” Gore told the Times. “That’s why DMV immediately began correcting the access error following a legal compliance review, ensured that no additional confidential information was disclosed to these entities, and has implemented several additional layers of review.”

The situation is further complicated by the fact that beginning in 2013, the DMV has issued driver licenses to people in the U.S. illegally who can provide proof of identity and California residency, according to the Times. At the time, government officials said that the information of license holders in the country illegally would not be shared with federal immigration authorities.

The DMV said that 83 of the license holders who had information accessed by federal agencies did not have proof of legal presence in the United States. Other Californians had their information accessed as part of tax and child support investigations.

In total, the San Diego and Santa Clary district attorney offices were responsible for improperly accessing the data of about 3,000 license holders. All people affected by the breach have been notified by the DMV.

Tim Erlin, the VP of product management and strategy at cybersecurity firm Tripwire, said that many breaches are not the result of malicious attacks, but a “consequence of misconfigurations.”

“In these cases, there’s no stereotypical ‘bad guy’ to arrest, but often a group of well-meaning, but overworked and under-skilled staff that either couldn’t keep up or just didn’t know any better,” Erlin said. “Finding and addressing misconfigurations can be automated, but you have to start with an understanding of how the systems should be configured in order to measure how they differ from that desired state.”

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

  • Empowering and Securing a Mobile Workforce

    What happens when technology lets you work anywhere – but exposes you to security threats everywhere? This is the reality of modern work. No longer tethered to desks, work happens everywhere – in the office, from home, on the road, and in countless locations in between. Read Now

  • TSA Introduces New $45 Fee Option for Travelers Without REAL ID Starting February 1

    The Transportation Security Administration (TSA) announced today that it will refer all passengers who do not present an acceptable form of ID and still want to fly an option to pay a $45 fee to use a modernized alternative identity verification system, TSA Confirm.ID, to establish identity at security checkpoints beginning on February 1, 2026. Read Now

  • The Evolution of IP Camera Intelligence

    As the 30th anniversary of the IP camera approaches in 2026, it is worth reflecting on how far we have come. The first network camera, launched in 1996, delivered one frame every 17 seconds—not impressive by today’s standards, but groundbreaking at the time. It did something that no analog system could: transmit video over a standard IP network. Read Now

  • From Surveillance to Intelligence

    Years ago, it would have been significantly more expensive to run an analytic like that — requiring a custom-built solution with burdensome infrastructure demands — but modern edge devices have made it accessible to everyone. It also saves time, which is a critical factor if a missing child is involved. Video compression technology has played a critical role as well. Over the years, significant advancements have been made in video coding standards — including H.263, MPEG formats, and H.264—alongside compression optimization technologies developed by IP video manufacturers to improve efficiency without sacrificing quality. The open-source AV1 codec developed by the Alliance for Open Media—a consortium including Google, Netflix, Microsoft, Amazon and others — is already the preferred decoder for cloud-based applications, and is quickly becoming the standard for video compression of all types. Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.