Florida DMV breach confirmed; hackers claim 200,000 driver records stolen

Potential identity theft and fraud exposure for 200,000+ Florida residents whose personal information including Social Security numbers were compromised.
A criminal armed with your address and Social Security number can impersonate you with alarming credibility.
The DAVID database breach exposed sensitive personal information that criminals can use to commit identity theft and fraud.
Mark

So Florida confirmed the breach, but they're not saying how many people were actually affected?

Mimi

Right. ShinyHunters claims 200,000 records, but Florida hasn't confirmed that number or even what information was taken from each record.

Luke

That's a significant gap. We know a breach happened, we know the entry point was a compromised police credential, but the actual scope is still a mystery.

Mark

How did the hackers get that credential in the first place?

Mimi

It was stored on a personal device belonging to a Plant City Police Department employee. That's how Florida says the attacker got in.

Luke

But ShinyHunters told reporters it was a password-reset flaw that let them compromise multiple accounts. Those two stories don't match.

Mark

Which one is true?

Mimi

Florida hasn't addressed ShinyHunters' version directly. They've just said what they found in their investigation—the compromised credential. Whether there was also a password-reset vulnerability, we don't know.

Luke

So we have the state's account of how the breach happened, and the hackers' account, and they contradict each other. That's important to flag.

Mark

What's the real danger here for people whose records might have been stolen?

Mimi

If someone has your Social Security number, address, birth date, and driver's license information, they can impersonate you convincingly. Open credit accounts, file taxes, commit fraud.

Luke

And the fact that this came from a government database makes it worse—people trust that information is secure there.

Mark

What should people do right now?

Mimi

Freeze their credit, monitor their accounts, be suspicious of any unsolicited messages claiming to be from the DMV.

Luke

But they're doing that while Florida still hasn't told them exactly what was taken or who was affected. That's a tough position to be in.

  • Over 200,000 Florida residents may now have their Social Security numbers, addresses, birth dates, and vehicle histories in the hands of a criminal extortion group with a documented history of large-scale data exploitation.
  • The breach entry point — credentials from a Plant City Police employee stored on a personal device — reveals how a single lapse in digital hygiene can unlock an entire state's driver database.
  • ShinyHunters tells a different story, claiming they exploited a password-reset vulnerability to move systematically through DAVID, even accessing an account linked to an FBI agent, a version Florida has neither confirmed nor fully refuted.
  • Florida has contained the intrusion and notified the Attorney General, but has yet to disclose exactly how many records were taken or what specific data was compromised, leaving affected residents in a prolonged state of uncertainty.
  • Security experts are urging Floridians to freeze their credit immediately and treat any unsolicited DMV communications as potential scams, while warning that a successful attack on one state's system often signals coming attempts on others.

In the quiet machinery of civic life, few acts feel more intimate than surrendering your identity to the state — your face, your signature, your Social Security number — trusting it will be held in confidence. On September 15, Florida's highway safety agency confirmed that this trust had been broken, as an extortion group known as ShinyHunters claimed to have extracted more than 200,000 driver records from the state's DAVID database through a single compromised credential. The breach is a reminder that the weakest link in any security architecture is rarely the system itself, but the human pathways that lead into it — and that the consequences of institutional vulnerability are borne most heavily by ordinary people who had no choice but to share what was taken.

On September 15, Florida's Department of Highway Safety and Motor Vehicles confirmed what many had feared since its internal investigation began eleven days earlier: the state's DAVID driver database had been breached. The agency moved to contain the intrusion after detecting it on September 4, and officials say no unauthorized access has occurred since — but the damage had already been done.

An extortion group called ShinyHunters claims to have stolen more than 200,000 driver records, each potentially containing Social Security numbers, addresses, birth dates, vehicle registration details, photographs, and signatures. This is not incidental data. It is the kind of comprehensive personal profile that allows a criminal to impersonate someone with convincing authority — to call a bank, apply for credit, or pose as a government representative.

Florida's investigation points to a single compromised credential belonging to an employee of the Plant City Police Department, improperly stored on a personal device. ShinyHunters disputes this, claiming they entered through a password-reset vulnerability that gave them access to multiple DMV and even FBI-linked accounts, downloading records beginning September 3 until the flaw was patched. Florida has not confirmed that account. The two versions of events remain unreconciled.

What Florida has not yet disclosed is nearly as consequential as what it has: the exact number of records accessed, the precise data fields exposed, and whether every compromised record included a Social Security number. ShinyHunters offered a screenshot of a record belonging to Jeffrey Epstein as proof of access, but the full scope of the breach remains officially unquantified.

ShinyHunters is a seasoned operation, previously linked to breaches at major corporations and known for voice-phishing campaigns that trick employees into surrendering credentials. Their ability to leverage a single legitimate access point into a state government system illustrates a persistent truth in cybersecurity: authenticated entry is often the hardest wall to build and the easiest to quietly walk through.

Florida is working with the state's Digital Service and Department of Law Enforcement, with a criminal investigation ongoing. For the 200,000 or more residents caught in the breach's shadow, the immediate guidance is practical and urgent: freeze your credit, monitor your accounts, and treat any message claiming to be from the DMV with deep suspicion. Security experts also caution that a method proven effective against one state's database rarely stays contained — other DMV systems may already be in someone's sights.

Florida's Department of Highway Safety and Motor Vehicles confirmed on September 15 that its driver database had been breached. The agency, known as FLHSMV, discovered the intrusion into its DAVID system—the Driver and Vehicle Information Database—on September 4 and moved quickly to contain it. No further unauthorized access has occurred since, officials said, but the damage was already done. An extortion group calling itself ShinyHunters claims to have stolen more than 200,000 driver records, complete with Social Security numbers, addresses, birth dates, and vehicle registration details.

The breach matters because it exposes the kind of information most people have no choice but to hand over to government agencies. A driver's license file contains far more than just a photo and an address. The DAVID system holds photographs, signatures, vehicle histories, insurance information, and other identifying data that authorized government users can access. In the wrong hands, this material becomes a toolkit for identity theft and fraud. A criminal armed with someone's address, birth date, Social Security number, and driver's license information can impersonate them with alarming credibility—calling a bank, applying for credit, or convincing someone they represent a government agency.

Florida's investigation traced the breach to credentials belonging to a single employee of the Plant City Police Department. Those credentials had been improperly stored on the employee's personal electronic device, where a criminal actor was able to access and exploit them. This explanation differs sharply from what ShinyHunters has claimed. The group initially told security researchers that it breached DAVID through a password-reset vulnerability, one that allegedly allowed it to compromise multiple accounts belonging to DMV employees and even an FBI agent. ShinyHunters said it then moved through the database systematically, downloading driver records beginning September 3, until it lost access as the flaw was being patched. Florida has not backed that account. For now, the password-reset story remains the hackers' version; the compromised police credentials are what the state has publicly identified as the actual entry point.

What remains unclear is nearly as important as what has been confirmed. Florida has not disclosed how many records were actually accessed or stolen, nor has it confirmed ShinyHunters' claim of 200,000 records. The agency has not specified what information was taken—whether all records contained Social Security numbers, or only some. ShinyHunters provided a screenshot of a record belonging to Jeffrey Epstein as proof of access, showing an address, Social Security number, birth date, driver's license information, and vehicle details. But without Florida's full accounting, the true scope of the breach remains unknown.

ShinyHunters is not a new threat. The extortion operation has been linked to attacks on Salesforce environments and major companies including Google, Cisco, and Match Group. More recently, the group has relied on voice phishing—impersonating IT support to trick employees into entering credentials or authentication codes into fake websites. They have targeted single sign-on accounts connected to Microsoft 365, Google Workspace, and Salesforce. The fact that they were able to exploit a single compromised credential to access a state DMV system underscores a broader vulnerability: once an attacker obtains legitimate access, other connected services may become accessible too.

Florida has notified the state Attorney General as required by law and is working with the Florida Digital Service and the Department of Law Enforcement. The criminal investigation is ongoing. Officials said additional information would be released at an appropriate time, but that time has not yet come. In the meantime, residents whose records may have been exposed face a waiting period filled with uncertainty. The breach creates an opening for scammers to send fake alerts claiming to be from FLHSMV, pressuring people to verify personal information or click malicious links. Security experts recommend that affected drivers freeze their credit with the three major bureaus, monitor their credit reports and bank accounts for suspicious activity, and be extremely skeptical of any unsolicited messages claiming to be from the DMV. The possibility that ShinyHunters or other attackers might use the same techniques against DMV systems in other states adds another layer of concern. If a method works against one government database, criminals often look for similar vulnerabilities elsewhere.

Florida has not confirmed that record count or publicly said exactly what information was taken.
— FLHSMV statement
The attacker took advantage of credentials belonging to one Plant City Police Department user that had been improperly stored on a personal electronic device.
— FLHSMV investigation findings
Quieres la nota completa? Lee el original en Fox News ↗
Contáctanos FAQ