ShinyHunters Claims Breach of Florida DMV's Restricted DAVID Database
The extortion group alleges the theft of 200,000 driver records, providing a high-profile record as proof of access.
The cybercriminal group ShinyHunters claims to have breached the Florida Department of Highway Safety and Motor Vehicles' (FLHSMV) restricted DAVID database. The group alleges it has stolen more than 200,000 driver records, marking a significant potential exposure of state-managed personal data.
To substantiate the claim, the threat actors published a screenshot of the record belonging to Jeffrey Epstein. This move is intended to prove they have gained unauthorized access to the DAVID system, which is the primary online platform used by the FLHSMV to manage driver and vehicle information.
The DAVID System and ShinyHunters
The DAVID system is not a public-facing portal but a restricted database designed for official use in tracking vehicle registrations and driver licensing. Because it serves as a centralized repository for state records, it is a high-value target for actors seeking large volumes of verified identity data.
ShinyHunters is a financially motivated extortion group active since approximately 2019 or 2020. The group has a documented history of targeting high-profile organizations and cloud-based platforms. Their operational model typically involves stealing sensitive data and attempting to extort the victim organization for payment to prevent the public release of the stolen information.
Implications for Data Privacy
A breach of a state DMV database is critical due to the nature of the data stored within. These records typically contain highly sensitive personally identifiable information (PII), including driver's license numbers, home addresses, signatures, and photographs.
Unlike a leaked password or email address, which can be changed, the data found in DMV records is largely static. When this information is compromised, it provides criminals with the necessary components to conduct identity theft and fraud on a massive scale. The ability to spoof government-issued identification can lead to unauthorized financial accounts being opened or the bypassing of security checks in various sectors.
Current Status
While ShinyHunters has provided a specific record as proof of access, the full extent of the breach remains to be officially confirmed. It is currently unclear how the group gained entry to the restricted system or if other state databases were compromised during the operation. Security researchers are monitoring the group's activity to determine if the 200,000 records will be leaked or if the group will successfully negotiate a payout.