Florida DMV Database Breached via Stolen Police Credentials
Hacker group ShinyHunters claims theft of 200,000 driver records from the state's DAVID system.
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed a significant security breach of its driver-record database. The incident exposes the sensitive personal information of thousands of residents and highlights a critical vulnerability in law enforcement access controls.
According to state officials, the breach of the Driver and Vehicle Information Database, known as DAVID, was facilitated by compromised credentials belonging to a user at the Plant City Police Department. The international cybercriminal organization ShinyHunters claimed responsibility for the attack, asserting they stole more than 200,000 driver records. To prove the validity of the theft, the group released a screenshot of the record belonging to the late Jeffrey Epstein.
The compromised data is extensive, including highly sensitive personally identifiable information (PII). Confirmed stolen data points include names, home addresses, Social Security numbers, dates of birth, and driver's license IDs.
The Role of the DAVID System
The DAVID system serves as a critical infrastructure tool, providing law enforcement and state agencies with immediate access to driver and vehicle records. Because of the sensitivity of this data, access is strictly regulated under the federal Driver’s Privacy Protection Act (DPPA). The DPPA is designed to prevent the unauthorized disclosure of personal information from state motor vehicle records to protect citizens from harassment and identity theft.
Industry and Legal Implications
The exposure of Social Security numbers and license IDs creates a severe risk of identity theft for the affected Florida residents. Beyond the immediate security threat, the state now faces substantial legal exposure. Under the DPPA, individuals can recover a minimum of $2,500 per violation for the unauthorized disclosure of their information. Given the claim that 200,000 records were stolen, the potential financial liability for the state could be immense if class-action litigation follows.
Next Steps and Monitoring
State authorities are currently working to secure the system and mitigate further unauthorized access. While the FLHSMV has confirmed the breach, the full extent of the data exfiltration remains dependent on the claims made by ShinyHunters. Security experts are monitoring the dark web to see if the full dataset is leaked or sold, which would further escalate the risk to the affected individuals. This breach underscores the danger of single-point failures in credential management, where a single compromised police account can grant access to a massive state-wide repository of citizen data.