A Single Password Opened the Door

Florida’s Department of Highway Safety and Motor Vehicles has confirmed that its DAVID driver database suffered a data breach, following claims by the ShinyHunters extortion gang that it compromised the system and stole more than 200,000 records. The breach is alarming not just for its scale, but for how easily it happened. A criminal actor was able to take advantage of a single Plant City Police Department user’s credentials that were improperly housed on the employee’s personal electronic device. One password. One personal device. Potentially hundreds of thousands of Floridians exposed.

On September 4, 2026, FLHSMV learned of the data breach, which was conducted by an international cybercriminal organization. The breach was carried out by what officials called an “international criminal organization,” but they did not identify the group. That group, however, identified itself. ShinyHunters, a cybercriminal group that hacks targets for sensitive information and then extorts them for a payment to delete it, announced on its dark-web site that the “Florida DMV” was its latest victim.

What Is DAVID — and What Could Hackers See?

DAVID is the Driver And Vehicle Information Database, a restricted lookup system run by FLHSMV that lets Florida police and government agencies pull a driver’s full record on demand — it exists so an officer at a traffic stop can confirm who is in the car. In other words, this is not a lightly populated system. It holds some of the most sensitive personal data the government collects.

As evidence of the breach, the attackers published a screenshot of a record belonging to Jeffrey Epstein that showed sensitive information, including an address, Social Security number, date of birth, driver’s license number, and registered vehicles. DAVID can contain sensitive information including driver’s license applications, photographs, signatures, addresses, vehicle histories, insurance information, and related records. It remains unclear how many drivers were affected and exactly what information was exposed. Florida has not publicly confirmed the 200,000 figure claimed by ShinyHunters.

A Troubling Discrepancy in the Story

The hackers claimed they exploited a password reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and an FBI agent. That account directly contradicts the state’s official version, which points to a single stolen set of police credentials stored on a personal device. The gap between those two explanations matters enormously. If the state is right, the exposed surface is every credential at every police department, sheriff’s office, and clerk with DAVID access — none of whom FLHSMV employs or manages devices for. That version has no patch.

The breach is the second time this month that hackers broke into a target that stores driver’s license information for millions of Americans, making it the second organization that hosts Americans’ driver’s license information to be hacked this month. The two hacks highlight how cybercriminals, whose jobs keep getting easier thanks to AI, can easily gain access to millions of Americans’ extremely sensitive personal information.

What Florida Drivers Should Do Right Now

The data breach was quickly mitigated and no further breach has occurred or is ongoing, according to FLHSMV. The agency is partnering with the Florida Digital Service and the Florida Department of Law Enforcement in its response to the data breach. Still, containment does not undo exposure. Experts recommend monitoring your financial accounts regularly — checking your bank, credit card, and online accounts for unauthorized transactions.

As one security expert noted, “The greatest concern is the permanence of this information. Consumers can replace a credit card or password, but they cannot easily replace their face, birth date, signature or identity history.” Floridians should also be on guard for phishing attempts disguised as official DMV communications — a common follow-up tactic after breaches of this kind. As this is an ongoing criminal investigation, further information will be released at an appropriate time in the future. Until then, the burden of vigilance falls squarely on the people whose data was put at risk.