TechNewsReel
Live

Florida DMV Database Breached via Police Employee's Personal Device

The ShinyHunters cybercriminal group has claimed access to the state's critical DAVID database, threatening to release sensitive driver and vehicle data.

TechNewsReel Newsroom · September 13, 2026

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has acknowledged a significant data breach of its Driver and Vehicle Information Database, known as DAVID. The intrusion was carried out by an international cybercriminal organization, placing sensitive state records in the hands of extortionists.

According to official reports, the FLHSMV detected the breach on September 4, 2026, one day after the hacking group ShinyHunters claimed to have gained access. The attack vector was traced back to a security failure at the local level: the credentials of a Plant City Police Department employee had been improperly stored on a personal electronic device, allowing the hackers to compromise the account and enter the system. ShinyHunters has since issued a deadline of September 11, 2026, to negotiate before the stolen data is released publicly.

The Role of the DAVID Database

The DAVID database serves as critical infrastructure for the state, designed for the immediate retrieval of driver and motor vehicle information by law enforcement and criminal justice officials. Because it is built for rapid access during field operations, the database contains high-value personally identifiable information (PII), including addresses, dates of birth, and photographs.

State officials emphasized that this incident is entirely distinct from a separate, larger breach involving 153 million driver's licenses. That previous leak was sourced from IDScan.net, a Louisiana-based identity verification company, and remains under investigation by the FBI.

Industry Implications

This breach is particularly damaging because it grants criminals access to the same authoritative data that police rely on for verification. By possessing this information, bad actors can more effectively facilitate identity theft and bypass financial verification safeguards that typically rely on the accuracy of DMV records. The incident highlights a recurring vulnerability in government cybersecurity: the "human element," where the use of personal devices for official credentials creates a backdoor into secure state systems.

Current Response

FLHSMV is currently partnering with the Florida Digital Service and the Florida Department of Law Enforcement (FDLE) to manage the response and mitigate further risk. In a statement released via social media, the FLHSMV noted that because this is an "ongoing criminal investigation, further information will be released at an appropriate time in the future."

Observers are now watching to see if the September 11 deadline will result in a massive data dump or if the state's partnership with law enforcement can neutralize the threat before the information is leaked.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.