TechNewsReel
Live

ShinyHunters Breach Florida's Law Enforcement Driver Database

A breach of the DAVID system, linked to police employee credentials, exposes sensitive motorist data to an international hacking organization.

TechNewsReel Newsroom · September 11, 2026

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has fallen victim to a data breach targeting its Driver and Vehicle Information Database, known as DAVID. The incident has placed sensitive personal information used by law enforcement and criminal justice officials at risk of public exposure.

An international cybercriminal organization identified as ShinyHunters claimed responsibility for the attack. The group has issued a deadline of September 11, 2026, to release the stolen files if a deal is not brokered. The breach was linked to the credentials of an employee from the Plant City Police Department. Additionally, some reports attribute the unauthorized access to a password-reset weakness within the system.

Legacy Systems and Funding Gaps

The DAVID database serves as a critical operational tool for Florida's law enforcement agencies, providing essential vehicle and driver data. The breach comes at a time of significant tension regarding the state's digital infrastructure. For the FY 2025-26 budget, Governor Ron DeSantis proposed $16 million for a "Motorist Modernization" initiative specifically designed to address legacy integration and improve licensing processes. However, state lawmakers did not accommodate this funding request, leaving the agency to manage aging systems.

Risks to Florida Citizens

The exposure of the DAVID database is particularly severe because of the nature of the data stored within. The system contains highly sensitive personally identifying information, including driver photos, home addresses, dates of birth, and Vehicle Identification Numbers (VINs). Security experts warn that this specific combination of data allows cybercriminals to bypass standard identity verification safeguards. This increases the risk of sophisticated financial attacks and identity theft targeting Florida residents, as the stolen data can be used to impersonate victims across various platforms.

Current Status

As the deadline set by ShinyHunters approaches, state officials have remained largely silent on the specifics of the mitigation effort. When asked for a statement regarding the breach and the looming deadline, FLHSMV spokesperson Carla Goff stated, "No comment at this time." It remains unclear exactly how much of the database was exfiltrated or if the hackers have already begun selling portions of the data on the dark web. Observers will be watching to see if the state attempts to negotiate with the group or if the data is released on the specified date.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.