The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed a data breach affecting its Driver and Vehicle Information Database (DAVID), following claims by the ShinyHunters extortion group. The agency stated that it became aware of the breach on September 4, 2026, and swiftly contained the incident, preventing further unauthorized access.
FLHSMV's investigation determined that the breach originated from compromised credentials belonging to a single user from the Plant City Police Department. These credentials were reportedly stored improperly on the employee's personal electronic device, leading to their exploitation by an "international cybercriminal organization."
The agency has notified the Florida Office of the Attorney General and is collaborating with the Florida Digital Service and Florida Department of Law Enforcement as part of its ongoing response. Further details are expected to be released as the criminal investigation progresses.
This confirmation comes after the ShinyHunters group claimed to have breached the DAVID database and stolen over 200,000 driver records. However, FLHSMV has not disclosed the number of records accessed or stolen and has not corroborated ShinyHunters' specific claim regarding the volume of data exfiltrated.
ShinyHunters had previously offered a different account of their access method, asserting they exploited a password reset vulnerability to gain entry to multiple DAVID accounts, including those of DMV employees and an FBI agent. The group claimed to have begun downloading associated HTML pages and images by iterating through DAVID record IDs starting on September 3.
As evidence of their access, ShinyHunters shared a screenshot of a DAVID record for Jeffrey Epstein, which contained sensitive personal and vehicle information. The group later indicated that they had lost access to the system, suggesting the vulnerability they exploited was being patched.
FLHSMV's findings regarding the compromised police account contradict ShinyHunters' claim of a password reset flaw being the initial point of compromise. The agency's statement focuses on the misuse of credentials rather than a system vulnerability.






