Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 15, 2026 · 7 min read

Florida DMV Breach: 200K Records via a Police Login

One officer in Plant City saved a work password somewhere it did not belong. That habit gave an extortion crew a door into DAVID, the state system holding every Florida driver's address, Social Security number and vehicle history.

Florida confirmed the breach on September 11, 2026, a week after it happened. ShinyHunters says it took more than 200,000 driver records; the Department of Highway Safety and Motor Vehicles has not confirmed any number at all. BleepingComputer published the confirmation along with the detail that undoes the usual breach narrative: nothing in DAVID was hacked.

Key Takeaways

  • The Florida Department of Highway Safety and Motor Vehicles confirmed on September 11, 2026 that its DAVID driver database was reached using one Plant City Police Department user's credentials.
  • FLHSMV found those credentials had been "improperly stored on the employee's personal electronic device," not obtained through any flaw in DAVID itself.
  • ShinyHunters claims more than 200,000 driver records were taken; FLHSMV has not confirmed how many were accessed or stolen.
  • The attackers published a DAVID screenshot showing address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles.
  • FLHSMV notified the Florida Office of the Attorney General and is coordinating with the Florida Digital Service and Department of Law Enforcement in an ongoing criminal investigation.
View through a rain flecked windshield of a quiet American suburban street on an overcast day, a parked sedan at the curb with its license plate out of focus

What Is DAVID, and What Does It Hold?

DAVID is the Driver And Vehicle Information Database, a restricted lookup system run by FLHSMV that lets Florida police and government agencies pull a driver's full record on demand. It exists so an officer at a traffic stop can confirm who is in the car. Its contents go well past that.

Per the Privacy Guides breach roundup, the exposed fields include "address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles," plus insurance and parking permits. Federal law already treats this as sensitive: the Driver's Privacy Protection Act bars a state DMV from disclosing personal information from a motor vehicle record outside a short list of purposes. Nobody consented to being in it. You cannot opt out of having a license.

How Did the Attackers Get In?

They logged in. FLHSMV's investigation found that "the attacker used compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee's personal electronic device." No exploit, no malware on a state server, no vendor in the middle.

Downloads began September 3, 2026. FLHSMV learned of it on September 4 and says it shut the access down: "The data breach was quickly mitigated and no further breach has occurred or is ongoing." Confirmation came seven days later. The Record reported that the group offered an alleged DMV record for Jeffrey Epstein as proof, a choice aimed at attention rather than leverage.

Why Doesn't ShinyHunters' Story Match the State's?

Because they describe different failures, and only one can be fixed with a patch. ShinyHunters claimed it "exploited a password reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and an FBI agent," according to BleepingComputer's account of the group's claims. FLHSMV's investigation landed on one stolen password from one downstream agency.

Most coverage treated that gap as a footnote. It is the story. If the attackers are right, Florida ships a fix and it ends. If the state is right, the exposed surface is every credential at every police department, sheriff's office and clerk with DAVID access, none of whom FLHSMV employs or manages devices for. That version has no patch. It has a policy and an annual audit, which is what was in place on September 3.

Is 200,000 a Confirmed Number?

No. It is a figure published by the people who committed the crime, uncorroborated by FLHSMV, which has declined to say how many records were touched. Treat it as a ceiling claimed by a narrator with every incentive to inflate.

Scale is also the wrong lens. Against the 153 million driver's license scans stolen from IDScan, this looks trivial. But IDScan lost scan events, many of them repeat visits by the same person. DAVID rows are people, one each, Social Security number and home address already joined to the name. Two hundred thousand complete identities is worse per victim than a hundred million partial ones, and the same class of records surfacing on dark web marketplaces is the predictable next step.

The Insider Problem DAVID Already Had

Police lookup systems have leaked for years with no outside attacker involved. An Associated Press review found officers and employees were fired, suspended or resigned more than 325 times between 2013 and 2015 over misuse of confidential databases, with 250 further instances of lesser discipline, and called the real total "surely far higher." One officer looked up addresses of women he found attractive; two Miami-Dade officers ran checks on a journalist after unflattering coverage.

Every control built since assumes a curious or malicious insider: justify each search, sign the agreement, pass the annual audit. The Plant City officer did none of that. They stored a password badly, and all of those controls held perfectly while an extortion crew walked in wearing the officer's badge. Same structural gap as officer misuse of Flock plate reader lookups: the audit log tells you who searched, never whether it was really them. Forty nine other states run a system like DAVID, and that gap exists in every one.

What Can Someone Do With Your License Number, Address and Birth Date?

They can become you at any institution that verifies identity by asking questions only you should be able to answer. That bundle is the answer key: previous addresses, vehicles you owned, your date of birth.

  • Synthetic identity fraud. A real Social Security number paired with a fabricated name builds a credit file that passes checks for years before anyone notices.
  • SIM swap. Carrier support staff verify callers with exactly this data. The FBI's Internet Crime Complaint Center recorded 1,611 SIM swapping complaints in 2021 with adjusted losses over $68 million, up from 320 complaints and roughly $12 million across the three preceding years combined.
  • Targeted phishing. A message quoting your plate, your insurer and your license expiry date does not read like a scam.

Which is why text message codes are the weak link: NIST Special Publication 800-63B classes verification over the telephone network as RESTRICTED and tells verifiers to watch for "device swap, SIM change, number porting, or other abnormal behavior" first.

What This Means for Your Inbox

FLHSMV did not lose email addresses, which is exactly what makes the next few months dangerous. An attacker holding your name, address and license number only needs to match an email to it from the commodity dumps already circulating. What lands in your inbox is then a message from "Florida DMV" quoting details a stranger should not have.

Expect the usual sequence: a breach notification lure asking you to check whether you were affected, then a reinstatement fee, because a suspended license is the one thing people click without thinking. The crew behind the claim of 284 million McKesson patient records monetizes attention as readily as data. One rule covers all of it: FLHSMV writes by postal mail and through its own portal, so any email claiming to be the Florida DMV about this breach is hostile until you navigate to the agency yourself.

What Should Florida Drivers Do Right Now?

  • Freeze your credit at all three bureaus. Free at Equifax, Experian and TransUnion, and as the FTC puts it, "nobody can open a new credit account in your name, including you."
  • Request an IRS Identity Protection PIN. A six digit number that stops someone else filing a return with your Social Security number, valid one calendar year and renewed each January.
  • Move two factor authentication off SMS. Authenticator app or hardware key on bank, email and carrier accounts, plus a port out PIN with your mobile provider.
  • Pull your own driver record. Check the FLHSMV portal for registrations or address changes you did not make.
  • Ask about a new license number. Some states reissue on proof of identity theft, the only step that actually invalidates the stolen record.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.