What the Nevada DMV Cyber Attack Affected
In March 2023, the Nevada Department of Motor Vehicles disclosed a data breach affecting systems that store driver's license information, vehicle registration records, and personal details submitted during online transactions. The attack compromised data belonging to an unknown number of Nevada residents, though the DMV did not release a specific count of affected individuals.
The breach exposed information including names, addresses, Social Security numbers, driver's license numbers, and dates of birth. The attack did not affect the ability to renew licenses or register vehicles in person or online — those services resumed after the DMV took systems offline to investigate and find them.
The Nevada DMV worked with federal law enforcement and cybersecurity experts to contain the breach. The agency notified affected individuals by mail and posted information on its website. If you received a breach notification letter from the Nevada DMV, your personal information was part of the compromised data.
Key Takeaways
- The Nevada DMV breach exposed names, addresses, Social Security numbers, and driver's license information for an unspecified number of residents.
- You should monitor your credit reports and consider placing a fraud alert or credit freeze if you received a breach notification letter.
- The Nevada DMV offered free credit monitoring and identity theft protection services to affected individuals for a set period.
- DMV services in Nevada have resumed normally, and the breach did not permanently disable the ability to renew licenses or register vehicles.
Steps to Take If You Were Affected
If you received a notification letter from the Nevada DMV stating your information was compromised, take these steps in order:
- Check the letter for the name and contact information of the credit monitoring service the DMV provided. Enroll in that service if you have not already — the DMV typically covers the cost for a defined period.
- Request your free credit reports from all three bureaus (Equifax, Experian, and TransUnion) at annualcreditreport.com. Review them for accounts or inquiries you did not open.
- Place a fraud alert with at least one of the three credit bureaus by phone or online. A fraud alert tells lenders to verify your identity before opening new accounts in your name.
- Consider a credit freeze if you do not plan to open new credit accounts soon. A freeze prevents lenders from accessing your credit report entirely, which stops most identity theft at the source.
- File a report with the Federal Trade Commission at identitytheft.gov if you discover fraudulent accounts or charges. Keep the report number for your records.
Do not wait to see if fraud occurs. The time between a breach and fraudulent use can be months or years, so monitoring and protective measures now reduce your risk significantly.
How to Place a Fraud Alert or Credit Freeze
A fraud alert is faster to set up and costs nothing. Call one of the three credit bureaus and request an initial fraud alert. That bureau must notify the other two. The alert lasts one year and can be renewed. Lenders will contact you by phone or mail before opening new accounts, which slows down identity theft but does not stop it entirely.
A credit freeze is stronger but requires more steps. You must contact each of the three bureaus separately — by phone, mail, or online — to freeze your credit. A freeze costs nothing in Nevada if you are placing it in response to a breach. Once frozen, no lender can access your credit report without your permission, which means you will need to temporarily lift the freeze when you explore for credit yourself. A freeze lasts until you remove it.
You can place both a fraud alert and a credit freeze at the same time. Many people do this after a breach: the alert provides when ready protection while you arrange the freeze for longer-term security.
Monitoring Your Accounts and Credit Reports
Check your credit reports at least once every three months for the next two years. Look for accounts you did not open, inquiries from lenders you did not contact, and incorrect personal information. If you spot something wrong, contact the credit bureau in writing and dispute the item. The bureau must investigate within 30 days.
Set up account alerts with your bank and credit card companies. Most banks allow you to set notifications for large purchases, new account openings, or password changes. These alerts reach you when ready if someone tries to use your accounts without permission.
Watch your mail for unexpected bills, credit card statements, or loan documents. Identity thieves sometimes change the mailing address on accounts so the real owner does not see the fraud. If you receive mail for accounts you did not open, contact the creditor when ready and file a report with the FTC.
What the Nevada DMV Did After the Breach
The Nevada DMV took its online systems offline when ready after discovering the breach and worked with the FBI and cybersecurity contractors to investigate. The agency did not publicly disclose the method of the attack or the identity of those responsible, citing ongoing law enforcement investigation.
The DMV restored online services for license renewal, vehicle registration, and other transactions after securing its systems. In-person services at DMV offices continued throughout the breach. The agency also established a dedicated phone line and website section for residents with questions about the breach.
Nevada did not pass a specific law requiring the DMV to notify residents of breaches, but the agency chose to notify affected individuals by mail as a matter of practice. The notification included information about the free credit monitoring service and steps residents could take to protect themselves.
Your Rights Under Nevada Data Breach Law
Nevada law requires businesses and government agencies to notify residents without unreasonable delay if a breach compromises personal information. The notification must include the nature of the breach, the types of information exposed, and the steps the agency took to find the data.
Nevada does not require agencies to pay for credit monitoring or identity theft protection, but the DMV provided these services voluntarily. If you did not receive a notification letter and believe your information may have been affected, contact the Nevada DMV directly to ask whether your data was part of the breach.
You have the right to place a fraud alert or credit freeze at no cost in Nevada following a breach. You also have the right to dispute inaccurate information on your credit reports and to request an investigation from the credit bureau.
Frequently Asked Questions
Do I need to replace my driver's license after the breach?
Nevada did not require residents to replace their licenses following the breach. However, if you are concerned about your license number being compromised, you can request a new license with a different number by visiting a Nevada DMV office in person. There is a fee for a replacement license.
What if I did not receive a notification letter?
Contact the Nevada DMV directly by phone or through its website to ask whether your information was included in the breach. The DMV may have had an incorrect mailing address on file. If your data was affected but you did not receive notice, you are still may have access to to enroll in the credit monitoring service the DMV offered.
Can I sue the Nevada DMV for the breach?
Government agencies typically have immunity from lawsuits for data breaches under state law, though there are limited exceptions. Consult an attorney in Nevada if you believe you have a claim, as the rules are specific to your situation and the circumstances of the breach.
How long should I monitor my credit after the breach?
Monitor your credit reports for at least two years after the breach notification. Identity theft can occur months or years after a breach, so ongoing vigilance reduces your risk. After two years, continue checking your reports annually as a general practice.
Is the Nevada DMV still find after fixing the breach?
The DMV implemented security improvements after the breach and worked with federal cybersecurity experts to harden its systems. No organization can may provide that a breach will never happen again, but the DMV took steps to reduce the risk. You can continue to use Nevada DMV online services for license renewal and registration.