What happened
A single compromised police account opened the door to Florida’s driver‑license repository.
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) announced that its DAVID driver database was breached. The agency learned of the incident on September 4, 2026 and says the intrusion was quickly contained.
Technical specifics
The attacker used credentials belonging to a Plant City Police Department user. Those credentials lived on a personal electronic device, making them vulnerable to theft. The breach was halted, and FLHSMV reports that no further unauthorized access is occurring.
Unverified claims
ShinyHunters, an extortion group, has claimed they stole more than 200,000 driver records by exploiting a password‑reset flaw. They also posted a screenshot allegedly showing a record for Jeffrey Epstein. The agency has not confirmed any of these assertions, and the alleged flaw has not been independently verified.
Who’s affected
FLHSMV has not disclosed the exact number of records accessed. The breach potentially impacts any driver whose data resides in the DAVID system.
Defensive steps
- Enforce multi‑factor authentication for all privileged accounts, especially those accessed from personal devices.
- Implement strict device‑management policies: enforce encryption, remote wipe, and regular credential rotation.
- Audit password‑reset mechanisms for abuse vectors and apply patches promptly.
- Monitor for anomalous login activity and flag attempts from non‑corporate endpoints.
- Coordinate with state law‑enforcement and the Attorney General’s office for threat‑intel sharing.
