Florida confirms DMV database breached via stolen police account
Florida confirms its DAVID driver database was breached using stolen police credentials; ShinyHunters claims theft of 200,000+ records.
The Florida Department of Highway Safety and Motor Vehicles confirmed a breach of its DAVID driver database, learned of on September 4, 2026, and says the breach was quickly mitigated with none ongoing. Investigators found the attacker used compromised credentials of a single Plant City Police Department employee that were improperly stored on a personal electronic device. The ShinyHunters extortion gang claims it stole more than 200,000 driver records starting September 3 and shared a Jeffrey Epstein record as proof; FLHSMV has not confirmed the count. The agency notified the Florida Attorney General's office and is working with the Florida Digital Service and Florida Department of Law Enforcement.
- ShinyHunters claims over 200,000 DAVID driver records stolen starting September 3
- FLHSMV attributes access to compromised credentials of one Plant City police employee
- Credentials were improperly stored on the employee's personal electronic device
- ShinyHunters earlier claimed a password reset flaw exposed accounts including an FBI agent's
- Record count and exfiltration claims remain unconfirmed amid an ongoing criminal investigation
Full article370 words · extracted from bleepingcomputer.com · click to collapse

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach after the ShinyHunters extortion gang claimed to have compromised the system.
The disclosure comes after the ShinyHunters extortion group claimed it breached the DAVID database and stole more than 200,000 driver records.
"On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization," the agency said in a statement posted to X.
"The data breach was quickly mitigated and no further breach has occurred or is ongoing."
FLHSMV says its investigation determined that the attacker used compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee's personal electronic device.
The agency says it has notified the Florida Office of the Attorney General of the breach and is working with the Florida Digital Service and Florida Department of Law Enforcement as part of its response.
"As this is an ongoing criminal investigation, further information will be released at an appropriate time in the future," FLHSMV said.
ShinyHunters claimed a different access method
FLHSMV's findings are different from how ShinyHunters previously claimed to have gained access to the database.
The hackers claimed they exploited a password reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and an FBI agent.
ShinyHunters said it then began iterating through DAVID record IDs and downloading associated HTML pages and images beginning on September 3.
As proof of the breach, the threat actors shared a screenshot of a DAVID record belonging to Jeffrey Epstein that contained sensitive personal and vehicle information.
ShinyHunters later told BleepingComputer that it had lost access to the system and believed the flaw was being patched.
FLHSMV has not disclosed how many records were accessed or stolen during the breach and has not confirmed ShinyHunters' claim that more than 200,000 records were taken.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/