Skip to main content
Emerging ThreatsData Breaches

Florida DMV Breach Exposed via Stolen Police Credentials

Florida DMV office interior with employees and security measures.

"On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization," the Florida Department of Highway Safety and Motor Vehicles said in a brief posted to X, a statement that confirmed a feared outcome after the extortion group ShinyHunters claimed it had compromised the DAVID driver database.

FLHSMV confirms breach, says incident was "quickly mitigated"

The agency identified the intrusion on September 4, 2026, and told the public that "the data breach was quickly mitigated and no further breach has occurred or is ongoing." FLHSMV said its investigation traced the attacker’s entry to compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on that employee’s personal electronic device. The department notified the Florida Office of the Attorney General and said it is working with the Florida Digital Service and the Florida Department of Law Enforcement as part of its response. FLHSMV also noted the matter is an ongoing criminal investigation and that "further information will be released at an appropriate time in the future."

How FLHSMV says the intruder gained access: a stolen police account

According to the agency’s statement, the attacker did not exploit a flaw in DAVID itself but instead used valid credentials from a single Plant City Police Department account. Those credentials, the agency said, had been improperly stored on the employee’s personal device and were then used to access the DAVID driver database. FLHSMV has not disclosed how many DAVID records were accessed or stolen as a result of the incident.

ShinyHunters’ version: a password-reset flaw and mass downloads

ShinyHunters, the extortion group that earlier claimed responsibility, offered a different narrative. The hackers told outside reporters they had exploited a password-reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and, they claimed, an FBI agent. ShinyHunters said it began iterating through DAVID record IDs and downloading associated HTML pages and images beginning on September 3. As proof, the group shared a screenshot of a DAVID record they attributed to Jeffrey Epstein containing sensitive personal and vehicle information. ShinyHunters later told BleepingComputer it had lost access to the system and believed the flaw was being patched.

Discrepancy over scale: ShinyHunters' 200,000-plus claim and FLHSMV's silence

ShinyHunters publicly asserted that more than 200,000 driver records were taken. FLHSMV has not confirmed that figure and has not released a count of records accessed or stolen. The agency’s description of entry via a single compromised Plant City Police Department credential differs materially from the threat actor’s claim of exploiting a password-reset vulnerability and moving laterally through multiple accounts. Those conflicting accounts remain the central unresolved technical question in the case.

What this means for the Florida Office of the Attorney General, Florida Digital Service, and Florida Department of Law Enforcement; Plant City Police Department; and drivers

  • Florida Office of the Attorney General, Florida Digital Service, and Florida Department of Law Enforcement: These agencies are explicitly named by FLHSMV as part of the response. They will oversee legal, technical and investigative activity tied to the ongoing criminal investigation and decisions about public disclosure, notifications, and potential enforcement actions.
  • Plant City Police Department: The breach report centers on credentials tied to a Plant City Police Department user. The department will likely need to examine credential storage policies and device handling for personnel — the agency’s role is central because its account credentials were identified by FLHSMV as the path of compromise.
  • Drivers and holders of DAVID records: FLHSMV has not released the number of records affected, leaving drivers uncertain about whether their personal or vehicle information was accessed. The presence of a screenshot of a DAVID record attributed to Jeffrey Epstein, shared by the threat actor, underscores that sensitive personal data was viewable in the system and that at least some records were copied outside state control.

The public facts are compact but consequential: FLHSMV detected a breach on September 4, 2026, traced access to compromised credentials from a Plant City Police Department user stored on a personal device, and says the intrusion was swiftly mitigated. ShinyHunters maintains a different account — alleging a password-reset flaw and mass downloads beginning the day before. FLHSMV has not confirmed the threat actor’s claim of more than 200,000 records taken, and the state’s law-enforcement partners and oversight offices are now engaged while a criminal investigation proceeds. The remaining questions are technical and numerical: how exactly the attacker moved from initial access to driver records, how many records were taken, and when the state will make those answers public.

Original reporting: https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/