ThreatPaper
Unverified

ShinyHunters breached DAVID through a password-reset flaw across multiple accounts including an FBI agent's

Assessment

FLHSMV's account is narrower on every point: one account, a Plant City Police Department user, credentials "improperly housed on the employee's personal electronic device." The state does not mention a reset flaw, other accounts, or the FBI, and the FBI has not commented. The two accounts can coexist, a stolen credential as entry and a reset weakness as expansion, but only the first has been confirmed. The group also said the flaw "was being patched"; if so, every other agency's DAVID users were exposed to it, and neither the flaw nor the fix has been described.

Where this claim appeared

BleepingComputer · 2026-09-08

https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

Florida DAVID Breach: One Officer's Stored Password, 200,000 Driver Records, and a Database With a History

Think this assessment is wrong? Report an error.