Florida Driver License Database Hacked: ShinyHunters Claims More Than 200,000 Records Stolen

Florida Confirms Driver License Database Breach After Hackers Claim More Than 200,000 Records Were Stolen

Florida Initially Declined to Confirm the Cyberattack, but FLHSMV Now Says Criminals Compromised a Police User’s Credentials and Accessed the State’s DAVID System. ShinyHunters Claims It Stole More Than 200,000 Driver Records, Though the State Has Not Confirmed That Number.

TALLAHASSEE, Fla. — Florida officials have now confirmed a cybersecurity breach involving the state’s Driver and Vehicle Information Database, dramatically escalating an incident that initially rested largely on claims made by the notorious cybercriminal group ShinyHunters. The Florida Department of Highway Safety and Motor Vehicles said it learned of the breach on Sept. 4 and determined that an international cybercriminal organization gained access using credentials belonging to a Plant City Police Department user that had been improperly stored on the employee’s personal electronic device.

That finding significantly changes the story from the initial reports. The central question is no longer whether Florida’s driver database was breached. The state says it was. What remains unresolved is the scale of the theft and exactly what information the attackers obtained. ShinyHunters has claimed it stole more than 200,000 Florida driver records, but FLHSMV has not publicly verified that figure or confirmed the full contents of the allegedly stolen dataset. The department says the breach was quickly mitigated and that no further unauthorized access is occurring. FLHSMV has launched an investigation with the Florida Digital Service and Florida Department of Law Enforcement and says additional information will be released when appropriate because the matter remains an active criminal investigation.

For millions of Florida drivers, however, the unanswered questions are substantial. If the hackers’ claims about the volume and sensitivity of the stolen information are ultimately verified, the breach could expose residents to long term risks involving identity theft, financial fraud, targeted phishing and other forms of criminal impersonation.

ShinyHunters Claims It Stole More Than 200,000 Florida Driver Records

ShinyHunters, a cybercriminal organization known for large scale data theft and extortion, claimed responsibility for compromising Florida’s DAVID system and says it obtained more than 200,000 driver records. Initial reporting indicated the group claimed the data included highly sensitive personal information and attempted to pressure its target through an extortion deadline.

The FBI has separately identified ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion. Federal authorities have warned that the group targets major organizations, steals sensitive information and uses threats of publication and other pressure tactics in attempts to extract payment from victims. The FBI has also cautioned that cybercriminal groups can exaggerate the amount or sensitivity of information they possess, making independent verification essential.

In Florida’s case, the underlying intrusion is no longer merely an allegation because FLHSMV has confirmed that a breach occurred. The claim that more than 200,000 records were stolen, however, remains unverified by the state. That distinction is critical. Confirmation that criminals accessed DAVID does not automatically confirm every assertion ShinyHunters has made about what it downloaded or how many Floridians were affected.

Florida DMV hacked

State Investigation Points to Compromised Police Credentials

Early reporting raised questions about whether attackers had exploited DAVID’s password recovery system or an unpatched vulnerability. FLHSMV’s subsequent investigation has now provided a different and more specific explanation. According to the department, the attacker took advantage of credentials belonging to a single Plant City Police Department user. FLHSMV said those credentials had been improperly stored on the employee’s personal electronic device, providing the criminal actor with a pathway into the system.

That finding is significant because it shifts the immediate focus away from an unconfirmed theory about a technical vulnerability in DAVID itself and toward credential security, access controls and the risks created when government login information is stored on personal devices.

The incident raises broader questions about how Florida protects credentials capable of accessing highly sensitive driver information. If one compromised user’s credentials were sufficient to provide meaningful access to the database, investigators will need to determine what authentication protections existed, whether multifactor authentication was required, what restrictions were placed on the account and whether unusual access patterns should have triggered automated security warnings.

The breach also illustrates a fundamental cybersecurity problem confronting government agencies and private companies alike: even a heavily protected central database can become vulnerable when legitimate credentials are compromised at the edge of the network. Security is only as strong as the authentication and access controls protecting the people authorized to enter the system.

DAVID Contains Highly Sensitive Information About Florida Drivers

DAVID, short for Driver and Vehicle Information Database, is used by law enforcement agencies and other authorized entities to access Florida driver and motor vehicle information. Because the system contains personal identifying information, unauthorized access carries potentially serious consequences even before investigators establish the full extent of the stolen data.

Driver information can be particularly valuable to criminals because identity data can be combined with information obtained from other breaches. Names, addresses, dates of birth, driver license information and Social Security numbers, when available, can help criminals construct detailed identity profiles used for financial fraud, account takeover attempts and convincing phishing attacks.

Unlike passwords, much of this information cannot simply be changed after a breach. A compromised password can be reset in minutes. A home address, date of birth or Social Security number may remain useful to criminals for years.

That is why the exact contents of the allegedly stolen records matter as much as the number of people affected. Florida officials will need to establish which fields were accessed, whether attackers merely viewed records or successfully extracted them, how long unauthorized access lasted and whether logs can establish precisely which records were compromised.

Florida Initially Stayed Quiet Before Confirming the Breach

The state’s response evolved rapidly as the story developed. When WCTV first reported the allegations, state officials had not confirmed that the hackers had successfully breached the database. The station reported that officials initially declined to comment while cybercrime monitoring sources circulated ShinyHunters’ claims. FLHSMV subsequently acknowledged that it had learned of the breach on Sept. 4 and publicly confirmed that an international cybercriminal organization had gained unauthorized access. The department said the incident was quickly mitigated and that no further breach had occurred or was ongoing.

The agency also confirmed that it notified the Florida Attorney General’s Office as required under state law and is coordinating its response with the Florida Digital Service and FDLE. Because the investigation is criminal and ongoing, FLHSMV says it will release additional information at an appropriate time. There are legitimate reasons for law enforcement and cybersecurity investigators to restrict information during the early stages of an active intrusion. Investigators may need to determine whether attackers remain inside a system, preserve forensic evidence, identify compromised credentials and close security vulnerabilities before publicly explaining what they know. Nevertheless, once the immediate threat has been contained, Floridians whose personal information may have been exposed have an equally legitimate interest in receiving timely and detailed information about what happened.

The 200,000 Record Figure Still Has Not Been Confirmed by Florida

The most important unresolved factual issue is the number of people affected. ShinyHunters claims it obtained more than 200,000 driver records, and that figure has been widely reported. Florida has confirmed the breach but has not publicly confirmed that more than 200,000 records were stolen. That distinction matters because extortion groups have an obvious incentive to maximize the apparent severity of an intrusion. The larger and more damaging the breach appears, the greater the pressure on the victim to pay. At the same time, ShinyHunters’ established history of major data-theft operations means its claims cannot simply be dismissed.

The responsible position is therefore straightforward: Florida’s DAVID system was breached, according to FLHSMV, while the hackers’ claim that they stole more than 200,000 records remains under investigation. State officials should ultimately provide a definitive number or the closest reliable estimate available. Floridians deserve to know whether the incident affected hundreds, thousands or hundreds of thousands of people.

Florida Law Requires Breach Notifications

Florida law establishes requirements for government entities and businesses dealing with breaches of personal information. Under Florida Statute 501.171, governmental entities are covered by the law’s breach notification provisions and must take reasonable measures to protect electronic personal information.

The law generally requires affected individuals to be notified when their personal information was, or is reasonably believed to have been, accessed as a result of a security breach. Notification must be provided as expeditiously as practicable and without unreasonable delay, generally no later than 30 days after determining that a breach occurred or that there is reason to believe one occurred. Law enforcement can request that individual notification be delayed when disclosure would interfere with a criminal investigation.

Florida law allows affected individuals to be notified through written notice sent to their mailing address or by email. Required notices generally must identify when the breach occurred or is believed to have occurred, describe the type of personal information involved and provide contact information consumers can use to obtain additional information.

The law also establishes notification requirements involving state authorities and, in sufficiently large incidents, nationwide consumer reporting agencies. FLHSMV has already said it provided the required security-breach notice to the Florida Attorney General’s Office.

Floridians Should Be Extremely Cautious About Phishing Attempts

The breach creates a second cybersecurity danger even for people whose information may not have been stolen. Criminals frequently exploit major data breaches by sending fraudulent emails and text messages pretending to come from the compromised organization. Floridians should therefore be extremely cautious about unsolicited messages claiming to come from FLHSMV, the DMV, law enforcement or another state agency concerning the breach. Messages demanding immediate action, requesting Social Security numbers or banking information, asking for payment, or directing recipients to unfamiliar links should be treated with suspicion.

The FBI has specifically warned that ShinyHunters and other cybercriminal actors use threatening messages and social-engineering tactics to pressure victims. Federal authorities recommend independently verifying unusual or urgent requests through established communication channels rather than responding directly to suspicious emails, texts or calls.

Anyone concerned about the Florida breach should navigate independently to official government websites rather than clicking links in unexpected messages. If Florida ultimately confirms that Social Security numbers or other high-value identity information were stolen, affected residents should consider additional protections such as monitoring their credit reports and placing fraud alerts or security freezes with the major credit bureaus.

Florida Needs to Tell Drivers Exactly What Was Stolen

The most important work now belongs to investigators.

Florida has confirmed the breach and identified compromised credentials belonging to a Plant City Police Department user as the access point. What the public still does not know is precisely what the attacker did after gaining access.

Investigators need to determine how long the credentials were compromised, when unauthorized access began, what portions of DAVID were accessed, whether records were merely viewed or downloaded in bulk, which data fields were exposed, how many individuals were affected and whether the attackers retained copies of the information.

The state should also explain what security measures existed before the breach and what has changed since. If credentials capable of accessing sensitive statewide driver information could be compromised through information stored on one employee’s personal device, Florida needs to determine whether stronger authentication, device-management policies, access restrictions or automated monitoring could have prevented the incident or reduced its scope.

Those questions are not about assigning blame before an investigation is complete. They are necessary to determine whether the same weakness exists elsewhere.

Florida Has Confirmed the Hack, Now Floridians Need to Know the Damage

This story has changed significantly since the first reports emerged. Florida’s driver database was not merely the subject of an unverified hacker boast. FLHSMV has now confirmed that a criminal actor gained unauthorized access using compromised credentials associated with a Plant City Police Department user. What remains unconfirmed is potentially even more important to individual Floridians.

ShinyHunters says it stole more than 200,000 records. Florida has not verified that number. The state has not yet publicly provided a complete accounting of which personal information was exposed or identified every individual potentially affected. Those answers need to come as soon as the criminal investigation allows. If the hackers exaggerated their haul, Florida should say so. If investigators determine that more than 200,000 driver records containing highly sensitive personal information were stolen, affected residents need to be told immediately and given clear instructions for protecting themselves.

The breach itself is now confirmed. The question facing Florida is no longer whether criminals got inside. It is how much they got once they were there.

Patrick Zarrelli - PJZNY -Sources

Sources & Further Reading

WCTV Eyewitness News — Thousands of Florida Driver Licenses Stolen, Hackers Say
https://www.wctv.tv/2026/09/10/thousands-floridians-driver-license-information-stolen-hackers-say/

WCTV Eyewitness News — Florida Driver’s License Database Breached, State Agency Confirms
https://www.wctv.tv/2026/09/10/florida-drivers-license-database-breached-state-agency-confirms/

Florida Department of Highway Safety and Motor Vehicles — Statement on Data Breach
https://www.flhsmv.gov/

Florida Senate — Florida Statute 501.171, Security of Confidential Personal Information
https://www.flsenate.gov/Laws/Statutes/2026/501.171

FBI Internet Crime Complaint Center — ShinyHunters Cybercriminal Group Advisory
https://www.ic3.gov/PSA/2026/PSA260515

BleepingComputer — Florida Confirms DMV Database Breached Via Stolen Police Account
https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/

Share this post :

Join the Conversation:

Want to join the conversation?

Create an account or sign in to share your thoughts, vote,
and reply to other readers.

No comments yet. Be the first to share your thoughts!