Florida's DMV Blames a Personal Device for a 200,000-Record Breach
Security / news
Florida's DMV Blames a Personal Device for a 200,000-Record Breach
FLHSMV says one stolen police credential explains the DAVID database breach; the extortion gang claiming credit describes a different way in.
Florida's Department of Highway Safety and Motor Vehicles said Sept. 11 that a single stolen credential, not the password-reset exploit the hackers claim, explains the Florida DMV breach. The credential belonged to an employee of the Plant City Police Department and had been stored on the employee's personal electronic device, the agency said in a statement.
The system in question is DAVID, the Driver and Vehicle Information Database that FLHSMV operates so police, courts and other government partners can look up driver records, vehicle registrations and Social Security numbers. Six days before FLHSMV's statement, the extortion group ShinyHunters had posted "State of Florida DMV" to its leak site, alongside a screenshot it said came from the system.
The two accounts of the breach do not agree. ShinyHunters told BleepingComputer it exploited a password-reset weakness that let it compromise multiple DAVID accounts, including ones belonging to DMV employees and an FBI agent. FLHSMV's own investigation, described four days later, names only the one compromised police login and does not mention a password-reset flaw at all.
What FLHSMV confirmed on Sept. 11
FLHSMV said it learned of the intrusion on Sept. 4 and that "the data breach was quickly mitigated and no further breach has occurred or is ongoing." It has notified the Florida Office of the Attorney General and is working with the Florida Digital Service and the Florida Department of Law Enforcement, according to the statement BleepingComputer published. The agency has not said how many records were accessed, citing an "ongoing criminal investigation."
The 200,000 records ShinyHunters claims
ShinyHunters told BleepingComputer it took more than 200,000 driver records: Social Security numbers, birth dates, addresses, license numbers and their issuance dates, registered vehicles, insurance details and parking permits. That figure comes from the gang, not from FLHSMV, and it has not been independently verified.
| Date | Event |
|---|---|
| Sept. 3 | ShinyHunters says its access to DAVID began |
| Sept. 4 | FLHSMV says it learned of the breach |
| Sept. 7 | ShinyHunters lists "State of Florida DMV" on its leak site |
| Sept. 11 | FLHSMV confirms the breach and names the single-credential cause |

ShinyHunters also told CyberInsider that FLHSMV "has not engaged in negotiations with them," and separately told BleepingComputer it has since lost access to the database and expects to announce further breaches "over the coming weeks." Neither claim is independently verified, and FLHSMV has not addressed either one.
A separate, larger exposure complicates the picture
The Florida DMV breach is not connected to a far larger 2026 exposure at IDScan.net, which involved roughly 153 million driver's license scans, CyberInsider reported. The two incidents share no confirmed link beyond both touching driver's license data, and treating them as one event would overstate what happened to DAVID.
A single set of internal credentials, reused or poorly stored, has been the entry point in other 2026 breaches, including Veradigm's third breach in two years. That is a different failure mode than the account-chaining that let a forum bug reach OpenAI's private code, but the outcome is the same: a boundary that depended on one person's judgment.
FLHSMV's version leaves out a detail ShinyHunters supplies on its own: an end date. The gang says its access is already gone. The agency has not said whether, or when, it will disclose how many Floridians' records were within the compromised account's reach.
Sources
More in Security
- 01WordPress 7.1.1 Closes the Click2Shell Remote Code ChainResearcher Paulos Yibelo's chain turned one clicked link into server-side code execution by tricking WordPress into silently installing a theme with no authorization checks at all.
- 02Oracle's September Update Fixes Six Perfect-10 BugsNone of the maximum-severity flaws is confirmed under attack yet, but Oracle is now shipping security patches on a monthly rather than strictly quarterly calendar.
- 03Mathspace Breach Exposes Data on 1.08 Million StudentsAttackers had 17 days between reaching Mathspace's reporting database and downloading it, and the company patched the underlying Metabase flaw only after both had happened.
- 04BragJack Hijacks AI Agents Built Into Five BrowsersA single malicious extension could seize Chrome's Gemini, Edge's Copilot, Opera Neon, Perplexity Comet and Claude in Chrome without bypassing any model's guardrails or writing a single injected prompt.