ShinyHunters hackers claim breach of Florida “DAVID” DMV database

A Florida DMV Database Breach Exposes 200,000 Drivers’ Records to Extortion Gang ShinyHunters

A disturbing cybersecurity incident has unfolded in the state of Florida, where hackers affiliated with the notorious extortion gang ShinyHunters claim to have breached a critical database managed by the Department of Motor Vehicles (DMV). The compromised platform, known as DAVID, contains sensitive information about over 200,000 drivers in the state. What’s more alarming is that the breach has been ongoing since September 3rd, with the threat actors releasing a screenshot of Jeffrey Epstein’s DMV record as proof of their access.

The ShinyHunters gang has made headlines before for targeting online web applications and cloud-based services to steal sensitive data. This time around, they claim to have exploited a password-reset flaw in DAVID, allowing them to compromise multiple accounts belonging to DMV employees and even an FBI agent. The threat actors say they used this access to iterate through driver records, downloading associated HTML and images for each entry.

The compromised database contains a treasure trove of sensitive information, including addresses, Social Security numbers, birth dates, driver’s license IDs, issuance and expiration dates, and registered vehicles. DAVID is described as the primary reporting mechanism for Fatalities and Serious Bodily Injury (FSBI) cases in Florida, highlighting the severity of this breach.

The ShinyHunters gang has a track record of using stolen credentials to gain access to connected services, allowing them to hijack single sign-on (SSO) accounts and steal customer data from cloud-based platforms. They have been linked to high-profile breaches involving companies like Salesforce, Google, Cisco, Pornhub, and Match Group.

In this latest incident, the threat actors claim they will leak the stolen data if their demands are not met. The Florida Highway Safety and Motor Vehicles agency (FLHSMV) has yet to comment on the breach, but a spokesperson for the agency confirmed that a password-reset flaw is being patched.

As the ShinyHunters gang continues to wreak havoc on digital platforms, it’s essential for organizations and individuals to remain vigilant. This incident serves as a stark reminder of the importance of robust cybersecurity measures, particularly when handling sensitive data. The fact that multiple states’ DMV platforms are being targeted using social engineering attacks raises concerns about the potential scope of this breach.

To mitigate such risks, it’s crucial to implement multi-factor authentication (MFA) and regularly update software and security patches. Organizations should also invest in employee education programs to prevent phishing attacks and ensure that sensitive data is handled securely. In the face of increasing cyber threats, staying informed and proactive will be key to protecting against future breaches.


Source: Bleeping Computer — 2026-09-08