ShinyHunters Claims Breach of Florida DMV Database
The hacking group alleges it stole over 200,000 records from Florida's DAVID system, setting a September 11 deadline for payment.
The hacking group ShinyHunters claims to have breached the Driver And Vehicle Information Database (DAVID), operated by the Florida Department of Highway Safety and Motor Vehicles (FLHSMV). The incident, if verified, would represent a significant compromise of state-managed personal identification data.
According to the group's claims, ShinyHunters has stolen more than 200,000 records from the DAVID system. To substantiate the breach, the group provided a purported driver record belonging to Jeffrey Epstein as proof of access. The extortionists have set a ransom and contact deadline of September 11, 2026, threatening to leak the stolen data if their demands are not met. As of September 8, 2026, the FLHSMV has not confirmed that a breach occurred.
Background on ShinyHunters
ShinyHunters is a financially motivated extortion group that has been active since approximately 2019. The group is known for targeting high-profile corporate entities and has been linked to numerous major breaches throughout 2026. Their operational pattern typically involves infiltrating sensitive databases and using the threat of public data dumps to coerce organizations into paying ransoms.
Legal and Privacy Implications
If the breach is confirmed, the exposure of these records triggers significant legal concerns under the Driver's Privacy Protection Act (DPPA). The DPPA is a federal law (18 U.S.C. § 2724) designed to restrict the disclosure of personal information from motor vehicle records to protect citizen privacy.
The act is particularly stringent because it allows for a private right of action. This means individuals whose data is knowingly obtained or disclosed for unauthorized purposes can seek statutory damages. In the context of a large-scale leak, the potential for widespread litigation against the responsible parties is substantial, as the law provides a mechanism for residents to seek financial compensation for the unauthorized release of their private information.
Current Status
While the group has presented evidence to support its claims, the state of Florida has yet to issue an official acknowledgment of the security failure. Cybersecurity analysts continue to monitor the September 11 deadline to see if the group follows through with a data dump or if a resolution is reached privately. Until the FLHSMV or an independent forensic audit confirms the intrusion, the full scope of the compromised data remains unverified.