Florida's DAVID Driver Database Breached: ShinyHunters Claims 200,000 Records Stolen
The **Florida Department of Highway Safety and Motor Vehicles (FLHSMV)** has confirmed a data breach affecting its **DAVID** driver database, following claims by the notorious **ShinyHunters** extortion gang. While the agency states the breach was mitigated, it acknowledges that compromised credentials led to unauthorized access, potentially exposing over 200,000 driver records.

The **Florida Department of Highway Safety and Motor Vehicles (FLHSMV)** has officially confirmed a data breach impacting its **DAVID** driver database. This disclosure comes in the wake of claims made by the **ShinyHunters** extortion group, which asserted it had compromised the system and exfiltrated more than 200,000 driver records.
According to **FLHSMV**, the agency became aware of the breach on September 4, 2026, attributing it to an "international cybercriminal organization." The department stated that the "data breach was quickly mitigated and no further breach has occurred or is ongoing."
**FLHSMV**'s investigation points to compromised credentials belonging to a single **Plant City Police Department** user. These credentials were reportedly stored improperly on the employee's personal electronic device, providing the entry point for the attacker.
In response, the agency has notified the **Florida Office of the Attorney General** and is collaborating with the **Florida Digital Service** and **Florida Department of Law Enforcement** as part of its ongoing response. **FLHSMV** noted that as this is an active criminal investigation, further information will be released at an appropriate time.
## ShinyHunters' Contradictory Claims
**FLHSMV**'s findings regarding the access method differ significantly from the claims made by **ShinyHunters**. The hacker group previously stated that they exploited a password reset flaw to gain unauthorized access to multiple **DAVID** accounts, including those belonging to **DMV** employees and even an **FBI** agent.
**ShinyHunters** reported that it began iterating through **DAVID** record IDs and downloading associated HTML pages and images starting on September 3. As evidence of the breach, the threat actors shared a screenshot of a **DAVID** record belonging to **Jeffrey Epstein**, which contained sensitive personal and vehicle information.
The group later informed BleepingComputer that they had lost access to the system, believing the vulnerability was being patched.
**FLHSMV** has not yet disclosed the exact number of records accessed or stolen during the breach, nor has it confirmed **ShinyHunters**' assertion that over 200,000 records were exfiltrated.