LmCast :: Stay tuned in

Florida confirms DMV database breached via stolen police account

Recorded: Sept. 11, 2026, 7:08 p.m.

Original Summarized

Florida confirms DMV database breached via stolen police account

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Artifactory flaws chained in attacks deploying backdoor malware

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

GitLab urges users to patch max severity path traversal flaw

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityFlorida confirms DMV database breached via stolen police account

Florida confirms DMV database breached via stolen police account

By Lawrence Abrams

September 11, 2026
03:00 PM
0

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach after the ShinyHunters extortion gang claimed to have compromised the system.
The disclosure comes after the ShinyHunters extortion group claimed it breached the DAVID database and stole more than 200,000 driver records.
"On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization," the agency said in a statement posted to X.
"The data breach was quickly mitigated and no further breach has occurred or is ongoing."
FLHSMV says its investigation determined that the attacker used compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee's personal electronic device.
The agency says it has notified the Florida Office of the Attorney General of the breach and is working with the Florida Digital Service and Florida Department of Law Enforcement as part of its response.
"As this is an ongoing criminal investigation, further information will be released at an appropriate time in the future," FLHSMV said.
ShinyHunters claimed a different access method
FLHSMV's findings are different from how ShinyHunters previously claimed to have gained access to the database.
The hackers claimed they exploited a password reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and an FBI agent.
ShinyHunters said it then began iterating through DAVID record IDs and downloading associated HTML pages and images beginning on September 3.
As proof of the breach, the threat actors shared a screenshot of a DAVID record belonging to Jeffrey Epstein that contained sensitive personal and vehicle information.
ShinyHunters later told BleepingComputer that it had lost access to the system and believed the flaw was being patched.
FLHSMV has not disclosed how many records were accessed or stolen during the breach and has not confirmed ShinyHunters' claim that more than 200,000 records were taken.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
IDScan confirms breach tied to 153 million stolen driver’s licensesShinyHunters hackers claim breach of Florida "DAVID" DMV databaseMathspace discloses data breach affecting over 1 million peopleIDScan sued over alleged data breach affecting 153 million driversNovocure data breach affects more than 1,400 cancer patients

Compromised Credentials
Data Breach
Database
Driver License
Florida
Police
ShinyHunters

Lawrence Abrams
Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

September Windows Server updates break Remote Desktop Services

Microsoft Excel KB5002914 update breaks copy and paste for some users

Sponsor Posts

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Overdue a password health-check? Audit your Active Directory for free

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has officially confirmed that its DAVID driver database experienced a data breach following claims made by the ShinyHunters extortion group. The agency stated that the breach, which involved the theft of more than 200,000 driver records, was quickly mitigated, preventing any further unauthorized access or ongoing breaches. The investigation by FLHSMV determined that the method of entry involved the attacker utilizing compromised credentials belonging to a single Plant City Police Department user, which had been improperly stored on the employee’s personal electronic device. In response to the incident, the FLHSMV notified the Florida Office of the Attorney General and initiated cooperation with the Florida Digital Service and the Florida Department of Law Enforcement to manage the response.

The findings from the state agency differ from the narrative presented by the threat actors. ShinyHunters alleged that they gained access by exploiting a password reset vulnerability to access multiple DAVID accounts, including those belonging to DMV employees and an FBI agent. They claimed that subsequent actions involved iterating through DAVID record IDs to download associated HTML pages and images, offering a screenshot of a record belonging to Jeffrey Epstein as evidence of the compromised data. However, the FLHSMV has not disclosed the exact number of records accessed or stolen, nor has it validated the extent of the 200,000 record claim made by the extortion group. The agency emphasized that as the matter remains an ongoing criminal investigation, further details will be released at a later time.