Incident
Published 2026-09-08
Verified 2026-09-19

Florida FLHSMV confirms DAVID DMV breach via stolen Plant City PD credentials

UPDATE 11 September 2026: the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a DAVID driver-database breach after ShinyHunters claimed compromise. In a statement posted to X (status 2098239548660514979), FLHSMV said it learned of the breach on 4 September 2026, that it was quickly mitigated, and that no further breach is ongoing. Investigation found attackers used compromised credentials of a single Plant City Police Department user that had been improperly stored on the employee’s personal electronic device. FLHSMV notified the Florida Office of the Attorney General and is working with the Florida Digital Service and Florida Department of Law Enforcement; further detail withheld pending the criminal investigation. FLHSMV has not disclosed how many records were accessed and has not confirmed ShinyHunters’ claim of 200,000+ records. ShinyHunters had claimed a password-reset flaw and multi-account access (including DMV/FBI accounts) iterating DAVID record IDs from 3 September — FLHSMV’s credential finding differs from that claim. Original 8 September desk card covered the unconfirmed extortion claim with Epstein DAVID screenshot as purported proof. No Australian nexus identified. Primary: FLHSMV X statement; wire: BleepingComputer (11 Sep).

Product
Florida DAVID (Driver And Vehicle Information Database) / FLHSMV
Versions
n/a (credential compromise of LE agency user)
Exploited in Australia?
unknown
Patch to
n/a for AU orgs; lesson: no LE/DMV credentials on personal devices; rotate exposed agency accounts

Primary: FLHSMV statement on X (4 Sep learn / posted around claim period) · Vendor: Florida FLHSMV · BleepingComputer (11 Sep 2026); earlier claim story 8 Sep

breaches identity