Skip to main content
Emerging ThreatsData Breaches

ShinyHunters Breaches Florida DMV Database

Florida DMV office interior with people waiting and a blurred computer screen in the background.

More than 200,000 Florida driver records were allegedly taken from the state's DAVID system after an extortion gang known as ShinyHunters said it exploited a password‑reset flaw to compromise accounts and then iterated through records by ID, downloading HTML pages and images, the group told BleepingComputer. The breach is said to have begun on September 3rd.

ShinyHunters' claim and the proof released

The extortion group added the Florida Highway Safety and Motor Vehicles (FLHSMV) to its data leak site and warned it would publish the stolen data unless the agency negotiated. As proof, the actors posted a screenshot of what they described as Jeffrey Epstein's record from the DAVID system. According to the material released, that record included an address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles.

The threat actors told BleepingComputer they have since lost access to the DAVID database and that the password‑reset flaw they used is being patched. BleepingComputer contacted FLHSMV and the FBI and said it would update the story if it received a response.

DAVID — the Driver And Vehicle Information Database

DAVID is the Driver and Vehicle Information Database platform operated by FLHSMV and is used by law enforcement and officials to look up driver information. The FLHSMV website describes the system this way: "The Driver And Vehicle Information Database (DAVID) is a multifaceted database that affords immediate retrieval of driver and motor vehicle information that is indispensable for law enforcement and criminal justice officials." The site also notes that "DAVID is the primary reporting mechanism for Fatalities and Serious Bodily Injury (FSBI)." The released screenshot shows tabs in the system interface for driver's license transactions, addresses, insurance, prior vehicles, and parking permits.

How ShinyHunters says it breached DAVID

ShinyHunters told BleepingComputer it exploited a password‑reset vulnerability to take over multiple accounts in the DAVID platform. Those accounts allegedly belonged to DMV employees and an FBI agent. Using the compromised accounts, the group said it enumerated records by ID, downloading the associated HTML pages and images for drivers. The actors claim this process allowed them to exfiltrate more than 200,000 records since the intrusion began on September 3rd.

The group also reported losing access after the initial compromise and said the password‑reset flaw is being patched. A separate source cited by BleepingComputer said the same threat actors are targeting other states' DMV platforms using social‑engineering attacks. When asked whether they were targeting additional DMVs, ShinyHunters told BleepingComputer they expect to announce other breaches in the coming weeks.

ShinyHunters: methods and recent activity

The name ShinyHunters has been associated with a series of data‑theft and extortion operations dating back to 2018. The actors commonly target online web applications and cloud SaaS environments, often exploiting stolen authentication tokens and single sign‑on (SSO) sessions to reach connected services. Over the past year the group has been identified as one of the more prolific actors conducting data theft and extortion against companies worldwide.

Reported tactics include breaches of third‑party integration companies to obtain tokens, voice‑phishing (vishing) that impersonates IT support to capture credentials and multi‑factor authentication codes, and device‑code vishing to obtain Microsoft account tokens. After stealing credentials and tokens, the actors have been described as hijacking SSO accounts to access services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox. The group has also been linked to a high‑profile May incident against Instructure Canvas, where the company later reached an "agreement" with the actors to prevent the stolen data from being leaked.

Despite arrests over the years tied to incidents bearing the ShinyHunters name — including alleged links to Snowflake data thefts, PowerSchool breaches, and the operation of the Breached v2 forum — actors using the ShinyHunters label continue to surface in new operations, according to reporting cited by BleepingComputer.

What this means for law enforcement, FLHSMV, and other states' DMVs

  • Law enforcement: DAVID is used daily by law enforcement and criminal justice officials, and FLHSMV characterizes it as indispensable for those users. A compromise of records or user accounts in DAVID could expose personally identifiable information tied to investigations and reporting; the actors claim some compromised accounts included an FBI agent.
  • FLHSMV (the agency): The agency's DAVID platform contains multiple tabs of driver‑related data and serves as the primary reporting mechanism for fatalities and serious bodily injury. FLHSMV was added to the ShinyHunters leak site and was contacted by BleepingComputer for comment; the outlet stated it will publish any response it receives.
  • Other states' DMVs: A source told BleepingComputer that the same threat actors are targeting other DMV platforms using social engineering. ShinyHunters told the outlet they expect to announce additional breaches, suggesting the group is actively seeking similar targets.

The immediate facts are narrow: actors claiming to be ShinyHunters say they used a password‑reset flaw to access DAVID accounts beginning September 3rd, extracted more than 200,000 records, posted a screenshot as proof, and later lost access as the flaw was patched. The only named public point of contact cited in reporting is BleepingComputer, which said it reached out to FLHSMV and the FBI for comment. Observers will watch whether the agency confirms the incident, what remediation steps it outlines, and whether additional state DMV systems are implicated in the days ahead.

Original BleepingComputer reporting