Florida DMV breach traced to compromised police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after attackers used credentials stolen from a Plant City Police Department employee. The agency says the breach was quickly mitigated and no ongoing intrusion exists, though it has not disclosed the number of records accessed. The ShinyHunters extortion group claimed responsibility, alleging the theft of over 200,000 driver records, but the state's account of the access method differs from the group's claims.
The breach was discovered on September 4, 2026, with FLHSMV stating that attackers leveraged credentials belonging to a single Plant City Police Department employee, credentials that had been improperly saved on that person's personal device. The agency emphasized that the intrusion was contained quickly and that no ongoing compromise exists, while coordinating with state law enforcement and the Attorney General's office.
ShinyHunters, however, offered a conflicting account, claiming they exploited a password reset vulnerability to access multiple DAVID accounts, including those of DMV staff and an FBI agent. As evidence, the group shared a screenshot of a record belonging to Jeffrey Epstein. The threat actors later stated they lost access and believed the flaw was being patched. FLHSMV has not confirmed the group's claim of over 200,000 records stolen.
This incident could affect Florida residents whose driver records may have been exposed, potentially enabling identity theft, fraud, or targeted harassment. The conflicting accounts of how access occurred may also erode public trust in state cybersecurity practices, particularly regarding how law enforcement credentials are safeguarded. If the larger record count is accurate, the impact could extend to financial and personal safety for many individuals, though the full scope remains unclear pending the ongoing investigation.