Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2761+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Florida Confirms DMV Database Breached via Stolen Police Account
Florida Confirms DMV Database Breached via Stolen Police Account
NEWS

Florida Confirms DMV Database Breached via Stolen Police Account

FLHSMV confirms its DAVID driver database was breached using credentials stolen from an officer's personal device, as ShinyHunters claims 200,000+ records.

Dylan H.

News Desk

September 11, 2026
4 min read

Florida DMV Confirms DAVID Database Breach

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID (Driver and Vehicle Information Database) system — used by law enforcement and officials to look up driver and vehicle records — suffered a data breach, following claims from the ShinyHunters extortion gang that it had stolen more than 200,000 driver records.

How the Breach Happened

FLHSMV's investigation attributes the intrusion to compromised credentials belonging to a Plant City Police Department employee, which had been improperly stored on that employee's personal electronic device. Using this single set of stolen credentials, the attackers gained access to the DAVID platform.

This account differs from ShinyHunters' own version of events: the group told BleepingComputer it exploited a password-reset vulnerability that let it compromise multiple accounts — allegedly belonging to DMV employees and an FBI agent — and then iterated through driver records by ID, downloading the associated HTML and images.

Timeline

  • September 3, 2026 — ShinyHunters begins exfiltrating DAVID records
  • September 4, 2026 — FLHSMV discovers the breach
  • September 7, 2026 — ShinyHunters lists "State of Florida DMV" on its extortion leak site
  • September 11, 2026 — ShinyHunters' self-imposed deadline passes; FLHSMV publicly confirms the breach

FLHSMV says the incident "was quickly mitigated and no further breach has occurred or is ongoing," and that it has notified the Florida Attorney General's office and is cooperating with law enforcement.

What Was Exposed

FLHSMV has not officially confirmed the number of records accessed or disclosed the full scope of exposed data. ShinyHunters claims to have pulled more than 200,000 driver records before losing access — which the group attributes to the underlying flaw being patched.

As proof, the attackers released a screenshot of a DAVID record belonging to Jeffrey Epstein, which reportedly included:

  • Home address
  • Social Security number
  • Date of birth
  • Driver's license ID, issuance and expiration dates
  • Registered vehicles

If accurate, similar data would be exposed for every affected driver record — a combination sufficient for identity theft, SIM-swapping, and targeted phishing or physical-security risks (the DAVID system is also used to look up law enforcement personnel).

Attribution

ShinyHunters is the international cybercriminal extortion collective behind a long run of high-profile breaches and Salesforce/Salesloft-linked data-theft campaigns throughout 2026. The group has increasingly targeted government and law-enforcement-adjacent systems, leveraging stolen employee credentials rather than novel exploits — underscoring that credential hygiene, not just software patching, remains a primary breach vector.

Notably, ShinyHunters says this incident is unrelated to a separate, previously reported exposure of roughly 153 million U.S. and Canadian driver's license scans tied to IDScan.net, despite having reportedly attempted to purchase that dataset from another actor.

Why This Matters

The breach illustrates a recurring failure mode: a single government employee storing credentials on a personal device was enough to compromise a statewide law-enforcement database used to look up sensitive driver and vehicle information. Organizations operating similarly sensitive lookup systems should treat this as a reminder to:

  • Enforce hardware-bound or phishing-resistant MFA for any account with access to PII lookup systems
  • Prohibit and technically prevent storage of credentials on unmanaged personal devices
  • Rate-limit and monitor bulk record-enumeration patterns (sequential ID lookups) that indicate scripted exfiltration
  • Audit password-reset flows for logic flaws that allow account takeover without the original credential

References

  • BleepingComputer — Florida confirms DMV database breached via stolen police account
  • The Record — Florida says motor vehicle data breach tied to credentials stolen from officer's personal device
  • BleepingComputer — ShinyHunters hackers claim breach of Florida "DAVID" DMV database
#Data Breach#ShinyHunters#Government#Florida#DMV#Credential Theft

Related Articles

Hacker Claims 3.6 Million Azure Account Records Stolen from Major Companies

A threat actor is selling employee databases allegedly taken from Microsoft Azure infrastructure of multiple Fortune 500 firms via compromised credentials.

5 min read

7-Eleven Data Breach Confirmed After ShinyHunters Ransom

7-Eleven has confirmed a data breach after ShinyHunters claimed to have stolen more than 600,000 Salesforce records containing personal information and...

5 min read

McKesson Confirms Data Breach as ShinyHunters' Deadline Looms

McKesson confirms unauthorized access to two business units after ShinyHunters claims 284 million records and demands ~$55M by Sept 1.

3 min read
Back to all News