TechNewsReel
Live

Florida DMV Database Breached: ShinyHunters Claim Theft of 200,000 Records

The extortion group ShinyHunters exploited a password-reset flaw to access the state's DAVID system, exposing sensitive driver data.

TechNewsReel Newsroom · September 12, 2026

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed a security breach of its Driver and Vehicle Information Database, known as DAVID. The incident, claimed by the extortion group ShinyHunters, has potentially exposed the sensitive personal information of over 200,000 individuals.

ShinyHunters alleges they stole more than 200,000 driver records, including Social Security numbers and photographs. To prove the validity of the breach, the attackers posted a screenshot of the DMV record belonging to Jeffrey Epstein. The group claims the intrusion was made possible by a password-reset flaw that allowed them to compromise multiple accounts within the system, including those of DMV employees and an FBI agent. The FLHSMV has since confirmed that the breach occurred via a stolen police account.

The Role of the DAVID System

The DAVID system serves as the primary repository for driver and vehicle information in Florida, providing essential data access to DMV officials and law enforcement agencies across the state. Because it centralizes highly sensitive personally identifiable information (PII), it is a high-value target for cybercriminals. ShinyHunters is a well-known data extortion group that specializes in targeting high-profile databases and utilizing dark web leak sites to pressure organizations into paying ransoms to prevent the public release of stolen data.

Industry and Legal Implications

The compromise of the DAVID database is particularly critical due to the nature of the data stored and the agencies that rely on it. The leak of 200,000 records exposes Florida citizens to significant risks of identity theft and financial fraud. Furthermore, the breach may trigger substantial legal liabilities under the Driver's Privacy Protection Act (DPPA), a federal law that restricts the release of personal information from state DMV records. The involvement of law enforcement credentials in the breach also raises urgent questions regarding the security of access controls for critical state infrastructure.

Next Steps and Unconfirmed Details

State officials are currently managing the aftermath of the breach, though the full extent of the data exfiltration remains under investigation. While the FLHSMV has acknowledged the use of a stolen police account, some reports have suggested the breach was facilitated by a compromised personal device belonging to a law enforcement officer; however, this specific detail has not been independently verified by primary security reporting. Observers are now watching for whether ShinyHunters will release the full dataset or if a ransom agreement will be reached.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.