Press play to start listening
Florida’s motor vehicle agency has confirmed suffering a data breach days after the ShinyHunters cyber extortion group claimed it had accessed the state’s Driver and Vehicle Information Database, known as DAVID.
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) said it learned of the breach on September 4, 2026. The agency described the attacker as an international cybercriminal organization but did not identify ShinyHunters by name.
FLHSMV said the incident was contained and that no further unauthorized access had occurred or was ongoing. Its investigation traced the breach to credentials belonging to a single user at the Plant City Police Department.
According to the department, those credentials had been “improperly housed” on the employee’s personal electronic device. FLHSMV did not explain how the attacker obtained them or whether the personal device itself had been compromised.
Official Findings Differ From ShinyHunters’ Account
The confirmation follows Hackread.com’s September 8 report on a ShinyHunters dark web listing naming the “State of Florida DMV” as a victim.
ShinyHunters told Hackread.com exclusively that it gained access to Florida’s DMV systems by exploiting the password-reset process on the agency’s portal. The group claims it compromised multiple authorized accounts, including an account linked to the FBI.
FLHSMV’s findings in its press release differ from the group’s account. The agency referred only to credentials belonging to a single Plant City Police Department user and did not mention a password-reset exploit, multiple compromised accounts, or an FBI-linked account.
“The Department immediately launched an investigation, which determined that a criminal actor was able to take advantage of a single Plant City Police Department user’s credentials that were improperly housed on the employee’s personal electronic device.”
FLHSMV
However, material reviewed by Hackread.com also includes a screenshot timestamped September 4, 2026, at 05:26:41, the same date FLHSMV says it detected the breach.
The timestamp supports ShinyHunters’ account that it had access on September 4, although it does not establish when the intrusion began.

Jeffrey Epstein Record Published as Evidence
ShinyHunters previously posted a proof archive containing an image that appeared to show convicted sex offender Jeffrey Epstein’s record inside DAVID.
The screenshot displayed Epstein’s photograph, signature, and an expired driver record. It also included a Social Security number, driver identification number, former address, physical details, and information about vehicles associated with the record.
Hackread.com published a redacted version of the image, removing the exposed identifiers. The interface was consistent with DAVID, which provides authorized government and law-enforcement users with access to Florida driver and motor vehicle information.
At the time, the screenshot supported ShinyHunters’ claim but could not independently confirm how the group obtained it. FLHSMV’s statement now confirms that a breach occurred, although the agency has not publicly confirmed that DAVID was the affected system or that the Epstein record came from this breach.
Analysis Finds More Than 600,000 ZIP Archives
ShinyHunters previously claimed it obtained more than 200,000 driver records. Hackread.com’s ongoing analysis of the material indicates that the exposed data extends well beyond basic driver records.
The compressed archive is approximately 52.3 GB and is divided into six folders containing ZIP files. The first folder alone contains 416,042 ZIP archives, while Hackread.com counted 612,982 ZIP files across all 6 folders.
That number should not be interpreted as 612,982 affected individuals. Multiple archives can relate to the same person, vehicle, transaction, or administrative process, and Hackread.com is still examining the material.
Files reviewed so far include front and back scans of US Social Security cards, US and international driving licenses, residence documents, employment authorization cards, and other identity records.
Hackread.com also identified vehicle ownership and transfer records, sale and purchase certificates, vehicle origin and safety documents, test records, requests, internal memoranda, and other administrative files.
Some of the identity documents reviewed by Hackread.com were issued by US federal agencies, including employment authorization cards bearing Department of Justice and Immigration and Naturalization Service branding. Hackread.com is withholding names, document numbers, and other identifying information.
Many of the identity documents and certificates are stored as directly viewable, unredacted scans. That makes the exposure more serious than a dataset containing only names, license numbers, or basic vehicle information.

Such material could support identity fraud, impersonation, targeted phishing, account-recovery abuse and other social-engineering attacks. Records connected to government personnel could also provide useful background information for attackers conducting more focused intelligence-gathering or account-compromise attempts.
Number of Affected People Still Unknown
FLHSMV has not disclosed what information was viewed or removed, how long the unauthorized user retained access, or how many Florida residents may be affected.
The agency also has not publicly addressed whether photographs, signatures, Social Security cards, employment authorization documents, or the broader collection of vehicle and administrative records identified by Hackread.com were taken during the breach.
FLHSMV said it submitted the required breach notice to the Florida Attorney General under Section 501.171 of the Florida Statutes. The law covers security incidents involving personal information and establishes notification requirements when Florida residents are affected.
The department is working with the Florida Digital Service and the Florida Department of Law Enforcement. It said more information would be released when appropriate because the case remains under criminal investigation.
Questions remain about the volume of data taken, the number of people affected, and the full method used to gain access. Hackread.com is continuing to analyse the material provided by ShinyHunters.

