Florida DMV Confirms DAVID Database Data Breach After ShinyHunters Claim
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed a data breach involving its DAVID driver database after the ShinyHunters extortion group claimed it had infiltrated the system and stolen more than 200,000 driver records.
FLHSMV said it learned of the incident on September 4, 2026, and quickly took steps to contain the breach.
“On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercrime organization,” the agency said in a statement posted on X.
“The data breach was quickly mitigated and no further breaches have occurred or are ongoing.”
Compromised credentials used to access Florida driver database
According to FLHSMV, investigators determined that the attacker used compromised credentials belonging to a user at the Plant City Police Department. The credentials were reportedly stored improperly on the employee’s personal electronic device.
The agency has notified the Florida Attorney General’s Office and is working with Florida Digital Services and the Florida Department of Law Enforcement as part of its investigation and incident response.
“As this is an ongoing criminal investigation, further information will be released at the appropriate time,” FLHSMV said.
ShinyHunters claimed a different attack method
FLHSMV’s findings differ from the access method previously described by ShinyHunters.
The extortion group claimed it exploited a password-reset vulnerability to access multiple DAVID accounts, including accounts belonging to DMV employees and FBI agents.
ShinyHunters said it began iterating through DAVID record IDs and downloading related HTML pages and images on September 3.
As evidence of the alleged intrusion, the attackers shared screenshots of DAVID records belonging to Jeffrey Epstein that included sensitive personal and vehicle information.
ShinyHunters later told BleepingComputer that it had lost access to the system and believed the vulnerability had been fixed.
FLHSMV has not confirmed the number of stolen records
FLHSMV has not disclosed how many records were accessed or stolen in the data breach. The agency also has not confirmed ShinyHunters’ claim that more than 200,000 driver records were exfiltrated.
The investigation remains ongoing, and additional details may be released as law enforcement and state agencies continue reviewing the incident.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



