New York Tuesday, September 15, 2026

Boldest Voice

Search

Technology

Florida DMV Confirms Data Breach After Hackers Claim 200,000 Driver Records Stolen

Florida officials have confirmed a data breach at the state's Department of Highway Safety and Motor Vehicles after the ShinyHunters extortion group claimed it stole more than 200,000 driver records from the DAVID database. The state says the breach stemmed from credentials belonging to a Plant City Police Department user that were improperly stored on a personal device, while the hackers blame a password-reset flaw.

DMV breach confirmed as hackers claim 200,000 records stolen

Florida officials have confirmed that the Florida Department of Highway Safety and Motor Vehicles, known as FLHSMV, suffered a data breach, following claims by the ShinyHunters extortion group that it accessed the state's Driver and Vehicle Information Database and stole more than 200,000 driver records.

The agency said it learned about the incident on Sept. 4, moved quickly to mitigate it, and has since seen no evidence of ongoing unauthorized access. Florida has not confirmed the number of records the hackers claim to have taken, nor has it publicly detailed exactly what information was exposed.

According to FLHSMV, its investigation traced the breach to credentials belonging to a single Plant City Police Department user. Those credentials, the agency said, were improperly stored on the employee's personal electronic device, allowing a criminal actor to take advantage of them. That account is the first official explanation of how the breach occurred, and it differs from the access method ShinyHunters has described.

The group originally told the cybersecurity news outlet BleepingComputer that it breached DAVID through a password-reset flaw, claiming the weakness let it compromise multiple accounts, including accounts belonging to DMV employees and an FBI agent. ShinyHunters said it then moved through DAVID record IDs and downloaded associated pages and driver files beginning Sept. 3, before later losing access and concluding that the password-reset issue was being patched.

Florida's investigation now points elsewhere. FLHSMV has not backed the claim that a password-reset flaw allowed multiple accounts to be compromised. For now, the password-reset explanation remains the hackers' version of events, while compromised police credentials are the access method the state has publicly identified.

ShinyHunters says it stole more than 200,000 driver records from DAVID. BleepingComputer reported that the group provided a screenshot of a DAVID record belonging to Jeffrey Epstein as evidence it had accessed the system. The screenshot reportedly contained an address, Social Security number, birth date, driver's license information and registered vehicle details.

DAVID can hold far more than basic driver's license information. Government records describing the system show that authorized users may have access to driver information, photographs, signatures, vehicle history, insurance information and other identifying records. Florida policy treats personal information in motor vehicle records as confidential, covering items such as Social Security numbers, driver identification numbers, addresses and medical or disability information.

FLHSMV has not disclosed how many records were accessed or stolen, and it has not confirmed the claim that more than 200,000 records were taken. The agency said it notified the Florida Office of the Attorney General as required under state law and is working with the Florida Digital Service and the Florida Department of Law Enforcement. The criminal investigation remains ongoing, and officials said additional information will be released at an appropriate time.

The agency's Bureau of Records manages access to driver records through DAVID for law enforcement and other approved entities, and the agency audits users for compliance. That kind of information can give criminals powerful material for identity theft. A caller who already knows a target's address, birth date and driver's license information can make a government impersonation scam far more convincing.

BleepingComputer previously reported that a source said the attackers were targeting DMV platforms in other states through social engineering, and ShinyHunters told the outlet it expected additional DMV breaches to surface. Florida has not confirmed that the current breach involved other state DMV systems. The possibility still deserves attention because state motor vehicle agencies hold information that is extremely valuable for identity fraud and targeted scams, and criminals who find a technique that works against one government system often look for similar access elsewhere.

ShinyHunters is an extortion operation associated with data theft attacks against companies and online services. Threat actors using the name have been linked to attacks in the past, and the group's claims in this case remain only partly corroborated by the state's public statements.

Austin Emerson

Author

Editorial Writer

Austin Emerson covers public affairs, politics, business, culture and daily news for Boldest Voice. The role focuses on verification, context, and clear explanations for readers.

Read on