Hackers Publish Hundreds of Thousands of Florida Vehicle Records After DAVID Breach

ShinyHunters has published hundreds of thousands of files taken from Florida's Driver and Vehicle Information Database, known as DAVID, the statewide system for vehicle and driver information TechCrunch.
The group said it entered DAVID earlier in September 2026 and posted the data to its leak site after the victim did not pay a ransom or cooperate with its demands. The release followed a short escalation. ShinyHunters first threatened to release allegedly stolen Florida DMV records, then claimed to hold more than 200,000 driver records, before posting what is now described as hundreds of thousands of files.
Florida's Highway Safety and Motor Vehicles agency, FLHSMV, confirmed in a September 2026 statement that DAVID was breached. The state account agrees with the attackers on which system was affected, but not on the exact volume taken.
FLHSMV said the attackers used a police officer's credentials stored on a personal device. DAVID is not a public web application. It is a query tool for law enforcement, where signed-in users can search records and their role sets what they can see.
Most of the published material is vehicle title paperwork. The set includes hundreds of thousands of certificates of vehicle ownership with buyer and seller names and addresses, plus vehicle identification numbers (VINs), the unique codes tied to each vehicle.
A smaller number of files included Social Security numbers and other government documents such as non-U.S. passports and immigration papers. The data reviewed did not appear to contain driver's licenses or people's photos.
As evidence of access, ShinyHunters posted a screenshot it said showed a DAVID record associated with Jeffrey Epstein.
The broader context here is credential sprawl around central state systems. Thousands of staff need DAVID for stops, investigations and administrative work, so each login is a possible entry point. Risk rises when logins leave managed devices and sit on personal hardware without phishing-resistant MFA, a login method built to resist fake sites, session controls or checks on device health.
In my view, operators of similar systems need structural fixes more than extra training. Short-lived credentials, hardware-backed logins, device checks before database access, and alerts for bulk searches would raise the cost of this exact path. High-profile samples are a familiar way to draw press attention and press victims during ransom talks. Title data stays valuable to criminals because it is structured, accurate and durable, and a name plus address plus VIN can link a person to a car, a location and another party in a sale. The lack of licenses and photos limits some direct impersonation, but the exposure for phishing, account takeover and synthetic identity building remains. Making central access harder to borrow and easier to revoke would leave this kind of bulk leak less repeatable.


