Florida confirms DAVID driver database breach tied to stolen Plant City police credentials as ShinyHunters claims 200,000+ records
FLHSMV confirmed its DAVID driver database was breached via credentials stolen from a Plant City police officer's personal device; ShinyHunters claims over 200,000 records stolen and had set a September 11 extortion deadline.
The ShinyHunters extortion group claims it breached the Florida Department of Highway Safety and Motor Vehicles' (FLHSMV) DAVID driver and vehicle database and stole more than 200,000 driver records, including photos and signatures, starting September 3, 2026. As proof, it published a screenshot of a Jeffrey Epstein record showing address, Social Security number, date of birth, license number, and registered vehicles, and set a September 11 deadline to negotiate before full publication. FLHSMV learned of the breach on September 4, publicly confirmed it on September 11, and says it was quickly mitigated with no ongoing intrusion. The agency attributes access to credentials of a single Plant City Police Department employee that were improperly stored on a personal electronic device; FLHSMV has not confirmed ShinyHunters' record count or exfiltration claims amid an ongoing criminal investigation. The access method is disputed: ShinyHunters claims it exploited a password-reset weakness and compromised employee accounts, including one belonging to an FBI agent, while the state points to the stolen police credentials. FLHSMV notified the Florida Attorney General's office and is working with the Florida Digital Service and Florida Department of Law Enforcement. Experts initially speculated a link to the separate, confirmed IDScan.net breach exposing over 153 million license scans under FBI investigation. Anthropic reported that suspected ShinyHunters affiliates use AI to scan stolen credentials, map systems, and exfiltrate data, in one case moving from a stolen developer token to cloud admin access in about three hours. The group has previously hit Jack Henry, McKesson, Ticketmaster, AT&T, ADT, and Rockstar.
- ShinyHunters claims theft of 200,000+ DAVID driver records starting September 3, 2026; FLHSMV has not confirmed the count
- FLHSMV learned of the breach on September 4 and publicly confirmed it on Thursday night, September 11
- FLHSMV attributes access to compromised credentials of a single Plant City Police Department employee improperly stored on a personal electronic device
- Access method is disputed: ShinyHunters claims a password-reset weakness and compromised employee accounts, including an FBI agent's
- Proof of access included a Jeffrey Epstein DMV record showing address, SSN, date of birth, license number, and registered vehicles
- Extortion deadline of September 11 was set before full publication of the data
- FLHSMV notified the Florida Attorney General's office and is investigating with the Florida Digital Service and Florida Department of Law Enforcement
- DAVID records include photos and signatures, raising identity-theft and synthetic-identity risk
Coverage timelineoldest first · each row is one article
- · 6d agoShinyHunters claims Florida DMV breach, puts data on the clock
CSO Online· 68
ShinyHunters claims it breached Florida DMV's DAVID database, stole 200,000+ driver records including SSNs, and set a September 11 extortion deadline.
- · 4d agoFlorida confirms DMV database breached via stolen police account
BleepingComputer· 75
Florida confirms its DAVID driver database was breached using stolen police credentials; ShinyHunters claims theft of 200,000+ records.
- · 4d agoFlorida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Record· 72
ShinyHunters breached Florida's DMV using credentials stolen from a police officer's personal device; the state confirmed the breach and is investigating.