The extortion group ShinyHunters claimed to have breached the DAVID platform of the Florida Department of Highway Safety and Motor Vehicles (FLHSMV), saying it stole more than 200,000 records linked to drivers in the state since the operation began on September 3, 2026.
The department uses the DAVID platform, an abbreviation for Driver And Vehicle Information Database, to provide law enforcement agencies and officials with access to driver and vehicle data. The department also relies on it as the primary reporting mechanism for deaths and serious injuries.
What Does the Group Claim?
ShinyHunters added FLHSMV to its data-leak site, threatening to publish the information it says it obtained unless the department entered negotiations with it. As evidence of the breach, the group published a screenshot of a record in the DAVID system belonging to Jeffrey Epstein, displaying personal data and information about registered vehicles.
According to what the group told BleepingComputer, access began through a flaw in the password-reset mechanism that enabled the attackers to take control of multiple accounts within the system. It says some of these accounts belonged to employees in the vehicle administration, in addition to a customer account belonging to the Federal Bureau of Investigation.
After gaining access, the group said it moved between record identifiers and downloaded the associated HTML files and images. According to the report, the records included data such as addresses, dates of birth, driver’s license numbers, insurance information, records of license transactions, previous vehicles, and parking permits.
What Has Changed in Practice?
ShinyHunters said it had lost access to the database and that the flaw used to compromise the accounts was being remediated. But the loss of access does not answer the most important question: How much data was actually copied, and were additional records accessed before the vulnerability was closed?
BleepingComputer contacted FLHSMV and the Federal Bureau of Investigation about the incident, but the report does not include a response from either of them as of publication. Therefore, the number of stolen records and the nature of the breach remain claims made by the attacking party and have not yet received independent confirmation from the system’s owner.
Signs of Broader Targeting
BleepingComputer quoted a source as saying that the attackers are also targeting platforms belonging to vehicle departments in other states using social-engineering attacks. ShinyHunters also said it expects additional breaches to be announced in the coming weeks, without providing verifiable details.
ShinyHunters is known for targeting web applications and cloud software environments, and for using stolen credentials and authentication tokens to access interconnected services. More recently, the group’s name has been linked to voice-phishing attacks targeting Okta, Microsoft, and Google accounts, including techniques intended to steal single sign-on and multi-factor authentication tokens.
Why Does This Matter?
The seriousness of the claim lies in the fact that DAVID does not appear to be a public-facing platform for users, but rather a centralized system that collects identifying and traffic-related data that could be highly sensitive. If the breach is confirmed, its impact would extend to drivers, employees, and entities that rely on the system, while questions concerning the number of affected records, the scope of the compromised accounts, and whether the data will actually be published remain open until an official confirmation is issued.