The ShinyHunters extortion crew listed the "State of Florida DMV" on its dark web leak site on September 7, 2026, claiming it stole more than 200,000 driver records from DAVID, the restricted Driver and Vehicle Information Database operated by the Florida Department of Highway Safety and Motor Vehicles (FLHSMV). As proof, the group published a screenshot of a driver record belonging to the late Jeffrey Epstein. The group set a September 11 deadline for the agency to make contact. As of publication, FLHSMV has not confirmed a breach, has not issued an incident notice, and according to what ShinyHunters told CyberInsider, has not entered negotiations. Everything below rests on attacker claims and journalist verification attempts, not on a victim statement or regulator filing.
What Happened
The sequence is consistent across outlets. ShinyHunters added FLHSMV to its leak site on the evening of September 7, framing the post as a "final warning" demanding contact before September 11, 2026. BleepingComputer, which spoke directly with the group, reports the claim covers "over 200,000 records about drivers in the state." Shattered.io reports the same 200,000-plus figure and adds that the theft began around September 3, 2026, a start date no other source in this set corroborates. TechNadu and CyberInsider report the listing and the deadline without attaching a record count at all, and both state plainly that they could not verify the claim.
DAVID is not a public portal. FLHSMV describes it as "a multifaceted database that affords immediate retrieval of driver and motor vehicle information that is indispensable for law enforcement and criminal justice officials," and notes it is the primary reporting mechanism for Fatalities and Serious Bodily Injury reporting. Access is restricted to law enforcement and other authorized government users, which is why a credible compromise here is materially different from a leaked marketing list.
Accounts differ on how much the proof screenshot actually proves. BleepingComputer treats the Epstein record as the group's proof of breach and describes its contents in detail. TechNadu is sharply more skeptical, noting the sample is an expired record and that historical Florida driver information tied to Epstein has previously surfaced in government investigative material, concluding that "the screenshot alone does not establish that ShinyHunters currently has unauthorized access to the DAVID system." CyberInsider says it could not independently verify the record's authenticity or whether the data came from a direct FLHSMV compromise. UnderCode News, working from a ThreatMon victim-listing alert rather than direct contact with the group, characterizes the activity as ransomware-related but supplies no evidence of encryption or intrusion mechanics. Treat that ransomware framing as unsupported: no other source describes encryption, and ShinyHunters operates as a data theft and extortion crew, not an encryptor.
What Was Taken
No independently verified inventory exists. The record count in circulation, more than 200,000, is the attackers' own figure, sourced to BleepingComputer's and Shattered.io's direct contact with the group and repeated nowhere authoritatively.
Per BleepingComputer's description of the proof screenshot, the exposed DAVID record contained address, Social Security number, date of birth, driver's license ID, issuance and expiration dates, and registered vehicles, with additional tabs for license transactions, address history, insurance, prior vehicles, and parking permits. TechNadu's read of the same image lists driver's license information, photograph, signature, address details, and vehicle records. CyberInsider describes DAVID's general contents similarly, including license applications, photographs, and signatures. The overlap is broad; the discrepancy worth flagging is that only BleepingComputer explicitly reports a Social Security number in the sample.
Two cautions on the number. First, ShinyHunters' counts are row counts, not people. Freshfromcache documents this directly: the group's claimed 284 million McKesson records was, in its own explanation to BleepingComputer, a raw line count, not a patient count, and the group said it had not finished processing the data. The same outlet traces how the Carhartt dump's 24.8 million machine-extracted email addresses shrank under closer analysis. Second, no source has published a sample beyond the single Epstein record, so 200,000 remains an assertion with a sample size of one.
This claim also appears unrelated to the parallel identity document exposure Krebs on Security reported on September 1, in which a dark web service called Nexus advertised digital scans of more than 153 million US and Canadian driver's licenses, apparently siphoned from a Louisiana-based identity verification company, and which drew an official inquiry from the FBI's New Orleans field office. CyberInsider reports that ShinyHunters previously tried to buy that dataset from Nexus but told them the Florida claim is separate. Do not conflate the two.
Why It Matters
A state motor vehicle agency is a single point of failure for identity in a way few private companies are. Driver's license number, SSN, date of birth, address history, photograph and signature is the complete package for synthetic identity fraud and document forgery, and unlike a password it cannot be rotated. If the 200,000 figure holds, that is 200,000 Floridians with a permanent exposure.
The law enforcement dimension raises the stakes further. DAVID is used by police and criminal justice officials, and one specific claim in the reporting deserves attention precisely because it is uncorroborated: CyberInsider reports that ShinyHunters told them they compromised accounts linked to FBI personnel with access to the state motor vehicle portal. No other source in this set repeats that detail and it has not been confirmed. If accurate, it would mean the query trail of federal investigators, and the lookup capability itself, sat in attacker hands. Unauthorized DAVID access has historically been a stalking and doxing vector, not just a fraud one.
Finally, this fits an escalating 2026 pattern. The same crew claimed 284 million records from McKesson in late August, an incident McKesson confirmed in an SEC Form 8-K as unauthorized access to third-party applications with data exfiltration, discovered August 25, with the company stating it had not determined the incident to be material. Retail, healthcare, and now, allegedly, state government infrastructure. Defenders should assume public sector agencies are now inside this group's target set.
The Attack Technique
Two sources report an intrusion method and they agree. ShinyHunters told BleepingComputer they breached DAVID through a password reset flaw that let them compromise multiple accounts. CyberInsider independently reports the group described a password reset exploit used to take over accounts with portal access. That is the extent of the technical detail available. No CVE, no vendor advisory, no confirmation from FLHSMV that such a flaw existed.
That method, if real, is notable for what it bypasses: an authentication reset abuse path defeats password strength entirely and, depending on implementation, can defeat weakly bound MFA. It also matches the crew's broader tradecraft. Freshfromcache observes that most of these intrusions begin with a phone call to someone at work, pointing at the social engineering and help desk manipulation that has characterized ShinyHunters campaigns. A password reset flow is the technical sibling of a help desk reset request. Both attack the recovery path rather than the credential.
TechNadu states flatly that the Florida data source and breach method remain unknown. Weigh the password reset account as the attackers' self-description, plausible and doubly reported, but unconfirmed.
What Organizations Should Do
- Audit your password reset and account recovery flows as a primary attack surface. Test for user-controlled reset token predictability, email or phone rebinding without step-up verification, and reset paths that bypass MFA enrollment. Treat recovery as equal in criticality to login itself.
- Enforce phishing-resistant MFA on privileged lookup systems, and verify the reset path cannot strip it. For law enforcement and criminal justice data systems, FIDO2 or PIV/CAC binding should be mandatory, with reset requiring in-person or supervisor-attested verification.
- Instrument query-level anomaly detection on sensitive record systems. Bulk retrieval of 200,000 records from a system designed for one-at-a-time lookups should trigger alerts on volume, velocity, off-hours access, and geographic anomaly. Rate limit per account.
- Review third-party and federated account access. McKesson's confirmed incident involved third-party applications; the Florida claim involves external agency accounts holding portal access. Inventory every non-employee identity with production data access and re-attest it.
- Do not treat attacker record counts as impact estimates. Build victim notification planning on your own data mapping, not on the leak site number. Row counts routinely overstate affected individuals by large multiples.
- Have a public posture ready before the deadline, not after. Silence during an extortion window cedes the narrative to the attacker. Even a neutral acknowledgment that an investigation is underway beats a vacuum, particularly for a public agency accountable to residents.
Sources: ShinyHunters Claims Florida DMV Breach, Epstein Proof | ShinyHunters hackers claim breach of Florida "DAVID" DMV database | McKesson discloses breach after ShinyHunters claims patient data theft | FBI Probes Service Selling 153M+ Drivers Licenses | ShinyHunters Claims Florida DMV Data Breach, Sets September 11 Dead... | ShinyHunters claims breach of Florida DMV, threatens data leak | ShinyHunters Claims Florida DMV as Latest Victim in Alarming Ransom... | Who is ShinyHunters? The name in your breach letters