A Florida DMV Database Breach Exposes Over 200,000 Drivers’ Personal Information
The ShinyHunters extortion gang has claimed responsibility for breaching an online platform used by the Florida Department of Motor Vehicles (DMV) to store sensitive information about drivers in the state. According to the threat actors, they have stolen over 200,000 records from the “DAVID” database, which includes details such as addresses, Social Security numbers, driver’s license IDs, and registered vehicles.
The breach was made possible by a password-reset flaw that allowed ShinyHunters to compromise multiple accounts in the system, allegedly belonging to DMV employees and an FBI agent. Using this access, the threat actors claim to have iterated through the records by ID and downloaded associated HTML and images for each driver, resulting in the massive data theft.
As proof of the breach, ShinyHunters released a screenshot of Jeffrey Epstein’s DMV record, which includes his address, registered vehicles, and other personal details. This move is likely an attempt to demonstrate the scope of the breach and pressure the FLHSMV agency into negotiating with them to prevent the stolen data from being leaked online.
The DAVID platform is used by law enforcement and officials to look up information about drivers in Florida. It’s a multifaceted database that contains vital records, including driver and vehicle information, which is indispensable for law enforcement and criminal justice officials. The fact that ShinyHunters was able to breach this system raises serious concerns about the security of sensitive data stored online.
ShinyHunters has been linked to numerous high-profile breaches over the past year, targeting companies such as Google, Cisco, Pornhub, and Match Group. They are known for using social engineering attacks and exploiting vulnerabilities in third-party integration companies to gain access to connected SaaS environments and steal customer data.
The FLHSMV agency has yet to comment on the breach, but it’s clear that ShinyHunters is not only targeting Florida’s DMV database. A source close to BleepingComputer revealed that the threat actors are also targeting other states’ DMV platforms using social engineering attacks. When asked about their plans, ShinyHunters stated that they expect to announce additional breaches over the coming weeks.
The breach of DAVID highlights the need for organizations to prioritize cybersecurity and implement robust measures to protect sensitive data from falling into the wrong hands. It’s essential for individuals to be vigilant and monitor their personal information online, checking for any suspicious activity or unauthorized changes to their records.
In light of this incident, it’s crucial for readers to take proactive steps to secure their own sensitive data. This includes regularly monitoring credit reports, being cautious when sharing personal details online, and using strong passwords and two-factor authentication whenever possible. By staying informed and taking the necessary precautions, individuals can minimize the risk of falling victim to similar breaches in the future.
Source: Bleeping Computer — 2026-09-08