The Florida Department of Highway Safety and Motor Vehicles confirmed that an attacker accessed its DAVID driver-information database using credentials assigned to a Plant City Police Department user. The agency said the credentials had been improperly stored on the employee’s personal device, learned of the incident on September 4, and has contained the breach; it says there is no ongoing intrusion. FLHSMV is investigating with the Florida Digital Service and other state authorities and has notified relevant Florida government offices.
The ShinyHunters extortion group claimed responsibility, alleging it exploited a password-reset weakness, accessed multiple accounts, and stole more than 200,000 driver records. It published purported screenshots of a DMV record linked to Jeffrey Epstein as evidence, but FLHSMV has not validated the alleged flaw, the claimed scope of access, or the record count. Officials initially considered a possible connection to the separate IDScan breach, though no link has been established.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
FLHSMV said it learned of a breach affecting its DAVID driver database. It determined that an international cybercriminal organization used compromised credentials for a single Plant City Police Department user that had been improperly stored on the employee's personal device.
ShinyHunters claimed it began iterating through DAVID record identifiers and downloading associated HTML pages and images. The group alleged that it ultimately obtained more than 200,000 driver records, a count FLHSMV has not validated.
FLHSMV said it quickly mitigated the intrusion and that no ongoing breach remained. The agency notified the Florida Office of the Attorney General and began coordinating its response with the Florida Digital Service and Florida Department of Law Enforcement.
ShinyHunters later said it had lost access to the DAVID system and believed the alleged password-reset flaw was being patched.
ShinyHunters claimed responsibility for accessing FLHSMV data and shared purported images of a DAVID record associated with Jeffrey Epstein as proof. The group asserted it used a password-reset flaw to access multiple DAVID accounts, an access method FLHSMV did not confirm.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.