TechNewsReel
Live

ShinyHunters Breach Florida DMV Database via Stolen Police Credentials

The compromise of the state's DAVID database follows a separate massive leak at private license-scanning vendor IDscan.net.

TechNewsReel Newsroom · September 11, 2026

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its Driver and Vehicle Information Database (DAVID) was targeted in a cyberattack by an international cybercriminal organization. The breach marks a significant security failure for the agency, exposing sensitive state records to external actors.

The attack was claimed by the cybercriminal group ShinyHunters, which posted a sample image from the DAVID database to its dark-web site as proof of the intrusion. The sample image purportedly showed the driver's license of Jeffrey Epstein. Following the leak, ShinyHunters established a deadline of September 11 for negotiations or contact regarding the stolen data.

The Point of Entry

Investigations into the breach revealed that the attackers gained access through stolen credentials. Specifically, the intrusion was linked to the credentials of an employee from the Plant City Police Department, which had been stored on a personal device. This vulnerability allowed the international organization to bypass security protocols and access the state's centralized vehicle and driver records.

A Pattern of Vulnerability

This incident follows closely on the heels of another massive security failure at IDscan.net, a private vendor providing license-scanning services to various companies. In that separate breach, hackers claimed to have stolen 160 million IDs. The IDscan.net leak included high-profile targets, including the driver's license of Defense Secretary Pete Hegseth, and remains under investigation by the FBI.

Industry Implications

The back-to-back compromises of a state government agency and a major private vendor underscore the extreme vulnerability of personal identification data. Because driver's licenses serve as primary identity verification across both public and private sectors, the aggregation of these records provides cybercriminals with a goldmine for identity theft and extortion. The Florida breach demonstrates that even centralized government databases are susceptible to simple credential theft if security hygiene is not maintained across all connected endpoints.

Current Status

While the FLHSMV has acknowledged the attack, the full extent of the data exfiltrated from the DAVID database has not been fully detailed. Security experts continue to monitor the dark web for further leaks. The removal of certain victims from hacker blogs often sparks debate over whether payments were made or if the data was simply moved. For now, the focus remains on the law enforcement investigation into the international group responsible for the intrusion.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.