ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Florida confirms DAVID DMV database breach via stolen police credentials as ShinyHunters claims 200,000+ driver records

highData breachimportance 75
What's new: The Record's later report (September 11, 20:00 UTC) adds timing detail: ShinyHunters claimed access Monday and FLHSMV publicly confirmed Thursday night; the state's confirmation itself was already covered in the previous summary from BleepingComputer's September 11 report (19:00 UTC).
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Florida's FLHSMV confirmed a breach of its DAVID driver and vehicle database, attributed to compromised credentials of a Plant City police employee improperly stored on a personal device; the ShinyHunters gang claims it stole 200,000+ records including SSNs,…

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed a breach of its DAVID driver and vehicle database. The agency learned of the breach on September 4, 2026, says it was quickly mitigated with none ongoing, and attributes the intrusion to compromised credentials of a single Plant City Police Department employee that were improperly stored on the employee's personal electronic device; The Record reports ShinyHunters claimed access Monday and FLHSMV publicly confirmed Thursday night. This attribution differs from the ShinyHunters extortion gang's own account, which claims it exploited a password-reset weakness to compromise DMV employee and FBI agent accounts and iterated through records by ID; the reports do not reconcile the two versions. ShinyHunters added FLHSMV to its leak site claiming theft of more than 200,000 driver records — including Social Security numbers — starting September 3, published a screenshot of Jeffrey Epstein's DAVID record (address, date of birth, SSN, license number and registered vehicles) as proof, and set a September 11, 2026 deadline before publication; its earlier account said access had been lost and the flaw was being patched. The deadline has now passed, but the reports do not indicate whether the data was published, and FLHSMV has not confirmed the record count or the exfiltration claims, which remain unconfirmed amid an ongoing criminal investigation. FLHSMV notified the Florida Attorney General's office and is working with the Florida Digital Service and the Florida Department of Law Enforcement. CSO Online notes DAVID records include photos and signatures, raising identity-theft and synthetic-identity risk. The incident is separate from a confirmed IDScan.net breach exposing over 153 million license scans (the Nexus database), which prompted an FBI investigation; experts had initially speculated a link between the two, but the state's attribution to stolen police credentials distinguishes the incidents. Separately, Anthropic reported that suspected ShinyHunters affiliates use AI to scan credentials, map systems and exfiltrate data, in one case moving from a stolen developer token to cloud admin access in about three hours; the group has previously hit Jack Henry, McKesson, Ticketmaster, AT&T, ADT and Rockstar, and says it is targeting other states' DMV platforms via social engineering with more leaks expected.

  • FLHSMV confirmed a breach of its DAVID driver and vehicle database, learned of on September 4, 2026, and says it was quickly mitigated with none ongoing; The Record reports ShinyHunters claimed access Monday and the public confirmation…
  • FLHSMV attributes the intrusion to compromised credentials of a single Plant City Police Department employee that were improperly stored on the employee's personal electronic device.
  • ShinyHunters claims it stole more than 200,000 driver records from DAVID starting September 3, 2026, including Social Security numbers; FLHSMV has not confirmed the count or the exfiltration claims, which remain unconfirmed amid an ongoing…
  • As proof, ShinyHunters published a screenshot of Jeffrey Epstein's DAVID record showing address, date of birth, SSN, license number and registered vehicles, and set a September 11, 2026 extortion deadline; the deadline has passed and the…
  • Access-vector accounts differ: ShinyHunters claims a password-reset weakness compromised DMV employee and FBI agent accounts (with access later reportedly lost and the flaw being patched), while FLHSMV points to stolen police credentials;…
  • FLHSMV notified the Florida Attorney General's office and is working with the Florida Digital Service and the Florida Department of Law Enforcement.
  • The breach is separate from a confirmed IDScan.net incident exposing over 153 million license scans (the Nexus database) under FBI investigation; experts initially speculated a link, but FLHSMV attributes DAVID access to stolen police…
  • CSO Online reports DAVID records include photos and signatures, raising identity-theft and synthetic-identity risk.

Coverage timeline

  1. · 7d ago
    BleepingComputer· 73
    ShinyHunters hackers claim breach of Florida "DAVID" DMV database

    ShinyHunters claims it breached Florida's DAVID DMV database via a password-reset flaw, stealing 200,000+ driver records including SSNs.