CSIDB logo
Incident

Florida Department of Highway Safety and Motor Vehicles

Incident posture

Attack window
Sep 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-10 17:14

Linked entities

Victim
Florida Department of Highway Safety and Motor Vehicles
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2026
Discovered
Undetermined
Disclosed
Sep 2026
Resolved
Pending

Summary

ShinyHunters asserted they infiltrated the Florida Department of Highway Safety and Motor Vehicles Driver and Vehicle Information Database by exploiting a password‑reset flaw that allowed them to compromise accounts of agency employees and an FBI agent. They then downloaded roughly two hundred thousand driver records containing personal details such as Social Security numbers and licence information, providing a screenshot of a Jeffrey Epstein record as proof while stating the vulnerability has since been patched.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

ShinyHunters claimed it breached DAVID, the Driver and Vehicle Information Database operated by the Florida Highway Safety and Motor Vehicles agency. DAVID is used to help law enforcement officials find details related to a particular driver. The group said the breach began on 3 September 2026 and involved records belonging to more than 200,000 drivers in Florida. On 7 September 2026, ShinyHunters added FLHSMV to its data leak site and stated, “Contact us, you know how. Or we will release the files.” To support its claim, the group released a screenshot of a record for Jeffrey Epstein, a Florida resident who was deceased at the time of the report. The displayed record included an address, Social Security number, birth date, driver’s licence ID, issuance and expiration dates, and registered vehicles.

ShinyHunters told BleepingComputer that it gained access to DAVID through a password-reset weakness. The group said this weakness allowed it to compromise multiple accounts inside the system. According to the hackers, the compromised accounts belonged to DMV employees and an FBI agent. ShinyHunters claimed it then misused that access to iterate through records by ID and download associated HTML and image files. The group also claimed it had since lost access to the system and that the password-reset flaw was being patched. Florida authorities and the FBI had not confirmed the threat actor’s claims when the BleepingComputer story was published. The reported impact centered on exposure of driver-record data from a law-enforcement database, including highly sensitive identity and licence details in the sample record released by ShinyHunters.

Sources

Sources available to members: 1 source.

CSIDB