Florida DAVID Breach: One Officer's Stored Password, 200,000 Driver Records, and a Database With a History
By Sethu Satheesh · 13 Sept 2026 · 14 min read
Threat Actor: ShinyHunters (self-claimed); FLHSMV: "an international cybercriminal organization" · Target: Florida Department of Highway Safety and Motor Vehicles — Driver And Vehicle Information Database
Source: www.bleepingcomputer.com
Executive Summary
On 11 September 2026 the Florida Department of Highway Safety and Motor Vehicles confirmed that its Driver And Vehicle Information Database, DAVID, had been breached by what it called "an international cybercriminal organization." The department said it learned of the intrusion on 4 September, that its investigation "determined that a criminal actor was able to take advantage of a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device," and that the breach "was quickly mitigated and no further breach has occurred or is ongoing." It has not said how many records were accessed, what was taken, or who is affected, and has referred the matter to the Florida Department of Law Enforcement, the Florida Digital Service and the Attorney General.
DAVID is not a public-facing DMV portal. It is the real-time query system Florida's law enforcement and criminal-justice agencies use at traffic stops and in investigations: driver photograph, signature, Social Security number, address history, emergency contacts, vehicle registrations, crash history. Access is by agency under a memorandum of understanding, governed by the federal Driver's Privacy Protection Act and Florida Statute 119.0712. Every Florida police department has accounts on it. That is the property the attackers exploited: a single officer's login, from a small department near Tampa, opened the state.
The attackers' account differs from the state's. ShinyHunters told BleepingComputer on 8 September that they breached DAVID "through a password-reset flaw" that let them "compromise multiple accounts in the system," including DMV employees' and an FBI agent's, then iterated through record IDs from 3 September, downloading each driver's HTML page and images, and took more than 200,000 records before losing access as the flaw was patched. As proof they published a screenshot of Jeffrey Epstein's DAVID record: address, Social Security number, licence details, registered vehicles. On 7 September they listed the Florida DMV on their leak site with a deadline of 11 September. On 11 September, after FLHSMV's statement, the listing was removed. Neither the state nor the group has said why.
The two accounts are not necessarily in conflict. A credential taken from an officer's personal device is an entry; a weakness in the password-reset process is a way to expand from one account to many. FLHSMV has confirmed the first and has not addressed the second, the 200,000 figure, or the FBI account. DAVID's history bears on all of it. WTSP's 2019–21 investigation found more than 900 state and local employees caught misusing the database since 2015, including 88 officers from 25 agencies who looked up a single person; the legislature responded with SB 890 in 2021, which raised the fine for misuse to $2,000 and added training. That law addressed authorised users abusing their access. It did not address an authorised user's password sitting on a phone.
Verification of Claims
-
Claim: FLHSMV confirmed a breach of DAVID discovered on 4 September 2026. → Verified → FLHSMV statement, 11 September: "On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization."
-
Claim: The entry point was one Plant City Police Department user's credentials stored on a personal device. → Verified as FLHSMV's finding → Statement: "a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device." Plant City PD has not commented. How the device was compromised is not stated.
-
Claim: The attackers exploited a password-reset flaw to compromise multiple accounts, including an FBI agent's. → Unverified → ShinyHunters to BleepingComputer, 8 September. FLHSMV's statement describes a single credential and does not mention a reset flaw, multiple accounts or the FBI. The FBI has not commented. The group also said the flaw "was being patched," which FLHSMV has neither confirmed nor denied.
-
Claim: More than 200,000 driver records were stolen. → Unverified → ShinyHunters' figure. FLHSMV "has not disclosed how many records were accessed or stolen." An ID-enumeration attack over the claimed window, 3–4 September, could plausibly reach that count; nothing published tests it.
-
Claim: Jeffrey Epstein's DAVID record was exposed. → Verified as a published screenshot → BleepingComputer and others reproduced the image, showing address, SSN, licence and vehicle fields. Its authenticity has not been confirmed by FLHSMV, but the state's confirmation of the breach two days later makes it the accepted proof-of-access.
-
Claim: The breach began on 3 September. → Unverified → ShinyHunters' date. FLHSMV gives only its discovery date, 4 September.
-
Claim: ShinyHunters removed Florida from its leak site after the state's statement. → Verified as reported → NBC News, 11 September: the group "deleted Florida reference" the same day. Flashpoint's Ian Gray: such deletions "often signal that negotiations may have occurred." No payment has been reported and the state has not commented.
-
Claim: The breach is connected to the IDScan.net driver's-licence leak. → False as an operational link → The two occurred in the same fortnight and both concern Florida-relevant driver data, and NBC covered them together, but IDScan is a private ID-verification vendor and DAVID is a state law-enforcement system, with different actors (an unattributed "Nexus" seller versus ShinyHunters) and different mechanisms. No source alleges a link.
-
Claim: DAVID has a documented history of misuse by authorised users. → Verified → WTSP "10 Investigates," 2019–21: more than 900 state and local workers caught misusing DAVID since 2015; 88 officers from 25 agencies accessed one person's record. Florida SB 890 (2021), signed 21 June 2021, raised the fine for misuse from $500 to $2,000 and mandated training.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| 2015–2021 | Florida agencies | 900+ employees caught misusing DAVID; 88 officers from 25 agencies query one individual. | WTSP |
| 21 June 2021 | Gov. DeSantis | Signs SB 890: DAVID misuse fine raised to $2,000; training required. | WTSP; Fla. Senate |
| 3 September 2026 | ShinyHunters (claimed) | Enumeration of DAVID records begins. | BleepingComputer, 8 Sept |
| 4 September 2026 | FLHSMV | Learns of the breach; investigation begins; breach "quickly mitigated." | FLHSMV statement |
| 7 September 2026 | ShinyHunters | Florida DMV listed on leak site; deadline 11 September; Epstein record screenshot published. | CSO Online; BleepingComputer |
| 8 September 2026 | ShinyHunters; BleepingComputer | Group describes password-reset flaw, multiple accounts incl. FBI agent, 200,000+ records; says access since lost. | BleepingComputer |
| 10 September 2026 | FLHSMV | Tells WCTV the incident is "not ongoing." | WCTV |
| 11 September 2026 | FLHSMV; ShinyHunters | Statement: single Plant City PD credential on a personal device; AG notified; FDLE and Florida Digital Service engaged. Leak-site listing removed. | FLHSMV; NBC News |
Attack Anatomy
Loading diagram...
What DAVID is
The Driver And Vehicle Information Database "affords immediate retrieval of driver and motor vehicle information that is indispensable for law enforcement and criminal justice officials," in FLHSMV's description, and is also the state's reporting system for fatal and serious-injury crashes. It returns the record an officer sees when they run a plate or a licence: photograph, signature, SSN, date of birth, addresses, emergency contacts, vehicles, insurance, permits, crash and citation history. Access is granted to agencies, not individuals; each agency signs an annual MOU, runs quarterly quality-control reviews of its users' queries, and is audited by FLHSMV every two years. The record type ShinyHunters described, "HTML files and images for each driver record," with tabs for prior vehicles, insurance and parking permits, matches DAVID's officer-facing interface.
Stage 1: the credential
FLHSMV's finding is that the credentials of one Plant City Police Department user were "improperly housed on the employee's personal electronic device." What that means, a note, a screenshot, a browser's saved password, a synced password manager, and how the device was compromised, infostealer, phishing, physical access, a breach of a consumer cloud account, the department has not said. Plant City is a department of about 80 sworn officers in Hillsborough County. Its user's account carried the same DAVID access as any other.
Stage 2: expansion, if it happened
ShinyHunters' claim is that from initial access they exploited "a password-reset flaw" to take over "multiple accounts," including DMV employees' and an FBI agent's. That is consistent with a reset flow that, once inside, lets an authenticated user trigger resets on others, or that leaks reset tokens. It is also consistent with the group inflating a single-credential intrusion. FLHSMV has confirmed one account and said nothing about others. If the flaw exists, the fix the group says was "being patched" is the material fact for every other DAVID user, and it has not been described.
Stage 3: enumeration
The group says it iterated through record IDs from 3 September and pulled each record's page and images. DAVID records are keyed; an authorised user can query by name, licence or plate, and sequential retrieval by ID at volume is the signature of automated collection rather than an officer's use. Whether DAVID rate-limits or alerts on that pattern is unknown; if it does, the alert fired on 4 September, one day in.
Stage 4: extortion
Listing on 7 September, deadline 11 September, proof-of-access a screenshot of the DAVID record for the most searchable name in Florida's files. The state confirmed the breach on the deadline day and the listing came down the same day. Florida statute forbids state agencies from paying ransoms; the delisting therefore has explanations other than payment, including that the group's leverage evaporated once the state had disclosed.
Threat Actor Profile
- Name / Alias: ShinyHunters, self-claimed. FLHSMV: "an international cybercriminal organization." The state has not named the group.
- Attribution basis: Claim to BleepingComputer with a data sample; leak-site listing. Consistent with the group's 2026 pattern (McKesson, Instructure, Aura) of credential-based access to institutional systems followed by a deadline.
- Motivation: Extortion. No encryption.
- Tradecraft in this case: No malware or exploit described; one set of stolen credentials, possibly an application-logic weakness, and automated retrieval. The proof-of-access choice was a media strategy.
- Divergence from official account: The group's version is broader than the state's on every axis, entry, number of accounts, an FBI account, and 200,000 records, and the state has confirmed none of the broader claims.
- MITRE ATT&CK techniques (verified on attack.mitre.org, 12 September 2026):
- T1552 Unsecured Credentials (credentials on a personal device; sub-technique not determinable)
- T1078 Valid Accounts (DAVID user account)
- T1119 Automated Collection (ID enumeration, as claimed)
- T1213 Data from Information Repositories
- T1657 Financial Theft (extortion)
Technical Indicators
# FLHSMV has published no indicators.
system: DAVID (Driver And Vehicle Information Database), FLHSMV
entry: one Plant City Police Department user account; credentials from a personal device
claimed_expansion: password-reset flaw; multiple accounts incl. DMV staff and an FBI agent (unconfirmed)
claimed_collection: sequential record-ID enumeration; per-record HTML + images; from 2026-09-03
claimed_volume: ">200,000 driver records"
fields_per_record_claimed: [address, SSN, DOB, DL number, issue/expiry, vehicles, prior vehicles, insurance, parking permits, photo]
extortion:
listed: 2026-09-07
deadline: 2026-09-11
delisted: 2026-09-11
proof: Jeffrey Epstein DAVID record screenshot
ip_addresses: []
domains: []
file_hashes: []Legal and Regulatory Response
State. FLHSMV has "provided the required security-breach notice to the Florida Attorney General's Office" under the Florida Information Protection Act (§501.171), which also requires notice to affected individuals within 30 days of determination of a breach. It is "coordinating with the Florida Digital Service and the Florida Department of Law Enforcement" and describes the matter as "an ongoing criminal investigation." No individual notifications have been reported, and the department has not stated a number to notify.
Federal. The Driver's Privacy Protection Act (18 U.S.C. §2721) governs disclosure of DMV records and provides a private right of action with $2,500 liquidated damages per violation for knowing disclosure; whether it reaches a criminal theft from a state system is a litigation question. If an FBI agent's DAVID account was compromised as claimed, that is a federal matter; the FBI has not commented.
Plant City. The police department has issued no statement. Whether the user was an officer or civilian employee, whether they remain employed, and whether the credential storage violated departmental policy are unknown.
Legislative. SB 890 (2021) increased the penalty for DAVID misuse by authorised users to $2,000 and required training, following WTSP's reporting on 900+ misuse cases. It did not address credential handling, multi-factor authentication, device restrictions or query-rate controls, none of which FLHSMV has described as in place.
Litigation. None identified as of 12 September 2026. With no confirmed count and no notifications, plaintiffs cannot yet establish standing.
Impact Assessment
- Breach confirmed — Confirmed. FLHSMV, 11 September.
- Entry vector — Confirmed by the state. One Plant City PD credential, personal device.
- Expansion to other accounts — Claimed by attacker. Unconfirmed.
- FBI agent's account — Claimed by attacker. Unconfirmed; no FBI comment.
- Records taken — Claimed. 200,000+. FLHSMV: no figure.
- Fields exposed — Reported. Full DAVID profile per record, per the Epstein screenshot.
- Duration — Claimed. 3–4 September. FLHSMV: "quickly mitigated."
- Ransom — Reported. Listing removed on deadline day; no payment reported; state agencies may not pay under Florida law.
- Individual notification — Not yet.
- Prior misuse history — Confirmed. 900+ cases since 2015.
Lessons and Defensive Recommendations
For agencies with DAVID access, and every equivalent system in every state
- The database's security is the security of its weakest user's phone. Multi-factor authentication tied to an agency-issued device is the control that would have stopped a stolen password. If DAVID does not enforce it, that is the finding of this incident, and FLHSMV should say whether it does.
- Rate-limit and alert on sequential record retrieval. An officer runs a plate; an attacker runs 200,000 IDs. The difference is visible in query logs on the first hour.
- Password-reset flows are attack surface. If the reset flaw ShinyHunters described exists, every agency user was exposed, and the fix should be disclosed to the agencies whose users it affected.
For FLHSMV
- The state's statement confirms the first hop and is silent on everything after it. The 200,000 figure, the FBI account and the reset flaw are all checkable in DAVID's own logs. Silence lets the attacker's number stand as the record.
- The 2021 reforms targeted insiders. The 2026 breach was an outsider with an insider's password. The controls are different, and only one set has been legislated.
For Floridians
- A DAVID record is the complete identity file: SSN, DOB, address history, photo, signature. If your record was among those taken, a credit freeze is the minimum. FLHSMV has not yet said who is affected; the FIPA notification, when it comes, will.
Sources
- BleepingComputer. "Florida confirms DMV database breached via stolen police account". 11 September 2026. Includes the FLHSMV statement.
- BleepingComputer. "ShinyHunters hackers claim breach of Florida 'DAVID' DMV database". 8 September 2026.
- The Record. "Florida says motor vehicle data breach tied to credentials stolen from officer's personal device". September 2026.
- NBC News. "Florida DMV says it was hacked shortly after major driver's license breach". 11 September 2026.
- Tampa Bay 28. "Plant City police employee credentials led to Florida DMV data breach: FLHSMV". September 2026.
- CSO Online. "ShinyHunters claims Florida DMV breach, puts data on the clock". 9 September 2026.
- WCTV. "Florida database breached; Incident not ongoing, state agency confirms". 10 September 2026.
- FLHSMV. "Driver And Vehicle Information Database (DAVID)". Archived 7 July 2026.
- WTSP 10 Investigates. "Gov. DeSantis signs law after 10 Investigates exposed abuse of access to your personal info". 22 June 2021; "Florida government workers abuse access to your private info".
- Florida Senate. SB 890 (2021), Bill Analysis.
- MITRE ATT&CK. T1552; T1078; T1119. Accessed 12 September 2026.
Related Research
ShinyHunters says it vished McKesson employees, took over Okta sessions, and pulled a terabyte from Salesforce and Snowflake between 20 and 25 August 2026. McKesson has confirmed exfiltration of patient data and nothing about how.
A copy of Postmark's MCP server, published to npm by someone unaffiliated with them, worked perfectly for fifteen versions. The sixteenth added one line — a BCC to an address the publisher controlled.
The transition of the global cyber threat landscape from traditional network intrusions to decentralized, identity-centric attacks is exemplified by the RedLine infostealer. First identified in March...