Florida DMV Confirms DAVID Database Breach
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID (Driver and Vehicle Information Database) system — used by law enforcement and officials to look up driver and vehicle records — suffered a data breach, following claims from the ShinyHunters extortion gang that it had stolen more than 200,000 driver records.
How the Breach Happened
FLHSMV's investigation attributes the intrusion to compromised credentials belonging to a Plant City Police Department employee, which had been improperly stored on that employee's personal electronic device. Using this single set of stolen credentials, the attackers gained access to the DAVID platform.
This account differs from ShinyHunters' own version of events: the group told BleepingComputer it exploited a password-reset vulnerability that let it compromise multiple accounts — allegedly belonging to DMV employees and an FBI agent — and then iterated through driver records by ID, downloading the associated HTML and images.
Timeline
- September 3, 2026 — ShinyHunters begins exfiltrating DAVID records
- September 4, 2026 — FLHSMV discovers the breach
- September 7, 2026 — ShinyHunters lists "State of Florida DMV" on its extortion leak site
- September 11, 2026 — ShinyHunters' self-imposed deadline passes; FLHSMV publicly confirms the breach
FLHSMV says the incident "was quickly mitigated and no further breach has occurred or is ongoing," and that it has notified the Florida Attorney General's office and is cooperating with law enforcement.
What Was Exposed
FLHSMV has not officially confirmed the number of records accessed or disclosed the full scope of exposed data. ShinyHunters claims to have pulled more than 200,000 driver records before losing access — which the group attributes to the underlying flaw being patched.
As proof, the attackers released a screenshot of a DAVID record belonging to Jeffrey Epstein, which reportedly included:
- Home address
- Social Security number
- Date of birth
- Driver's license ID, issuance and expiration dates
- Registered vehicles
If accurate, similar data would be exposed for every affected driver record — a combination sufficient for identity theft, SIM-swapping, and targeted phishing or physical-security risks (the DAVID system is also used to look up law enforcement personnel).
Attribution
ShinyHunters is the international cybercriminal extortion collective behind a long run of high-profile breaches and Salesforce/Salesloft-linked data-theft campaigns throughout 2026. The group has increasingly targeted government and law-enforcement-adjacent systems, leveraging stolen employee credentials rather than novel exploits — underscoring that credential hygiene, not just software patching, remains a primary breach vector.
Notably, ShinyHunters says this incident is unrelated to a separate, previously reported exposure of roughly 153 million U.S. and Canadian driver's license scans tied to IDScan.net, despite having reportedly attempted to purchase that dataset from another actor.
Why This Matters
The breach illustrates a recurring failure mode: a single government employee storing credentials on a personal device was enough to compromise a statewide law-enforcement database used to look up sensitive driver and vehicle information. Organizations operating similarly sensitive lookup systems should treat this as a reminder to:
- Enforce hardware-bound or phishing-resistant MFA for any account with access to PII lookup systems
- Prohibit and technically prevent storage of credentials on unmanaged personal devices
- Rate-limit and monitor bulk record-enumeration patterns (sequential ID lookups) that indicate scripted exfiltration
- Audit password-reset flows for logic flaws that allow account takeover without the original credential