LmCast :: Stay tuned in

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

Recorded: Sept. 8, 2026, 5:01 p.m.

Original Summarized

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

News

Featured
Latest

Trezor data breach impact now reaches 81,000 customers

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

N-able patches max severity N-central flaw amid ongoing attacks

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

OpenAI says ChatGPT outage causes image generation errors

August updates trigger 0xc0000409 errors on Windows Server 2016

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityShinyHunters hackers claim breach of Florida "DAVID" DMV database

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

By Lawrence Abrams

September 8, 2026
12:35 PM
0

The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
As proof of the breach, the threat actor has released a screenshot of Jeffrey Epstein's DMV record, including his address and registered vehicles.
DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver.
"The Driver And Vehicle Information Database (DAVID) is a multifaceted database that affords immediate retrieval of driver and motor vehicle information that is indispensable for law enforcement and criminal justice officials," reads a description on the FLHSMV website.
"DAVID is the primary reporting mechanism for Fatalities and Serious Bodily Injury (FSBI)."
Last night, ShinyHunters added FLHSMV to its data leak site, warning that it would leak the allegedly stolen data if the agency did not negotiate with them.

Florida DMV listed on the ShinyHunters data leak site
As proof of the breach, the threat actors released a screenshot of Jeffrey Epstein's record in the DAVID system. This record includes the person's address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles.
The system also has tabs for additional information, including driver's license transactions, addresses, insurance, prior vehicles, and parking permits.
ShinyHunters told BleepingComputer they breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system. These accounts allegedly belonged to DMV employees and an FBI agent.
Using this access, the threat actors say they iterated through the records by IDs and then downloaded the associated HTML and images for the drivers. This allegedly allowed them to steal over 200,000 data records since the breach began on September 3rd.
The threat actors told BleepingComputer that they have since lost access to the database and that the password-reset flaw used to compromise accounts is being patched.
BleepingComputer contacted FLHSMV and the FBI yesterday about the incident and will update the story if we receive a response.
A source told BleepingComputer that the threat actors are also targeting other states' DMV platforms using social engineering attacks.
When asked whether they are targeting additional DMVs, ShinyHunters told BleepingComputer they expect to announce other breaches over the coming weeks.
Who is ShinyHunters
ShinyHunters is an extortion gang known for targeting online web applications and cloud SaaS environments in data theft attacks.
The name ShinyHunters has long been associated with numerous threat actors who have conducted data breaches since 2018.
Over the past year, threat actors using the ShinyHunters name have become one of the most prolific groups that conduct data theft and extortion attacks against companies worldwide.
Initially focusing on Salesforce and other cloud SaaS environments, the threat actors are linked to a growing number of breaches involving companies such as Google, Cisco, PornHub, and online dating giant Match Group.
The extortion gang commonly breaches third-party integration companies and uses stolen authentication tokens to access connected SaaS environments and steal customer data.
More recently, the threat actors have been conducting voice phishing (vishing) attacks targeting Okta, Microsoft, and Google single sign-on (SSO) accounts, where they impersonate IT support staff to trick employees into entering credentials and multi-factor authentication (MFA) codes on phishing sites.
As BleepingComputer first reported, the ShinyHunters group has also adopted device code vishing attacks to obtain Microsoft account authentication tokens.
After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
The extortion gang was also behind a massive data-theft attack on Instructure Canvas in May that caused significant outages to the platform. The company eventually reached an "agreement" with the threat actors to prevent the data stolen in a recent breach from being leaked online.
Over the years, numerous arrests have been linked to the ShinyHunters name, including suspects connected to the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.
However, even with these arrests, threat actors using the ShinyHunters name remain a threat to enterprises worldwide.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
Novocure data breach affects more than 1,400 cancer patientsErnst & Young data breach claimed by ShinyHunters extortion gangClop created custom web shell for Windchill data theft attacksData analyst sent to prison for stealing data, extorting employerWesco confirms security incident after ExfilSquad claims data theft

Data Theft
Department of Motor Vehicles
DMV
Extortion
Florida
Password Reset
ShinyHunters

Lawrence Abrams
Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Sponsor Posts

Unify ransomware protection and recovery for every client

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

CTI Starter Kit + 2026 SANS CTI Survey

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

ShinyHunters extortion gang has claimed responsibility for breaching the online platform hosting the Florida Department of Motor Vehicles database known as DAVID, allegedly stealing over 200,000 driver records. The DAVID system functions as the Driver and Vehicle Information Database, managed by the Florida Highway Safety and Motor Vehicles agency, serving as an indispensable reporting mechanism for law enforcement and criminal justice officials related to Fatalities and Serious Bodily Injury. As evidence of this intrusion, the threat actors released a screenshot from the system pertaining to Jeffrey Epstein, which included sensitive details such as address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles, along with access to additional information like insurance and prior vehicles.

The attackers alleged that they gained access to DAVID through a vulnerability in the password reset mechanism, which allowed them to compromise multiple accounts believed to belong to DMV employees and an FBI agent. Using these compromised credentials, the threat actors reportedly iterated through records using IDs and subsequently downloaded the associated HTML and images for the drivers, resulting in the exfiltration of the large volume of data since the breach commenced on September 3rd. The threat actors stated that they have since lost access to the database, yet they claim that the flaw used for initial account compromise is currently being patched. In response to the incident, BleepingComputer contacted both the Florida Highway Safety and Motor Vehicles agency and the FBI for updates. Furthermore, a source indicated that ShinyHunters is actively targeting other state DMV platforms using social engineering tactics, and they have signaled an intent to announce additional breaches in the coming weeks.

ShinyHunters is recognized as an extortion group specializing in data theft targeting online web applications and cloud software as a service environments. Historically, this group has been associated with numerous data breaches since 2018, focusing initially on platforms like Salesforce and other cloud SaaS environments. Their methods frequently involve breaching third-party integration companies and leveraging stolen authentication tokens to access connected SaaS environments to steal customer data. More recently, the group has adopted voice phishing or vishing attacks aimed at Microsoft, Google, and Okta single sign-on services, impersonating IT support personnel to trick employees into revealing login credentials and multi-factor authentication codes on malicious websites. By hijacking these single sign-on accounts, the threat actors can subsequently breach connected enterprise services including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox. Beyond direct data theft, the group was also responsible for a significant data-theft attack on Instructure Canvas in May, which caused service outages, leading to an eventual agreement with the platform to prevent further data leakage from that incident. Throughout their history, arrests have been linked to the ShinyHunters name concerning various activities, including data-theft operations involving Snowflake and breaches at PowerSchool.