The extortion group ShinyHunters claims to have breached an online platform used by the Florida Department of Highway Safety and Motor Vehicles, stealing more than 200,000 driver records and threatening to publish the data if the state does not respond by a set deadline.
A Password-Reset Flaw Allegedly Opened the Door
The targeted system, known as DAVID (Driver And Vehicle Information Database), is described by the Florida Highway Safety and Motor Vehicles agency as a platform that gives law enforcement and criminal justice officials immediate access to driver and vehicle information, and serves as the state’s primary reporting mechanism for fatalities and serious injuries. ShinyHunters told BleepingComputer the intrusion exploited a password-reset weakness that let the group compromise multiple internal accounts, including ones it claims belonged to DMV employees and an FBI agent. Using that access, the group said it wrote a script to iterate through driver records by ID number, downloading the associated HTML pages and images for each one, collecting over 200,000 records since the breach allegedly began on September 3, 2026.
Epstein Record Used as Proof, September 11 Deadline Set
As evidence of the intrusion, the group released a screenshot of a DMV record belonging to Jeffrey Epstein, including his address and registered vehicles. ShinyHunters added the Florida agency to its dark web leak site with a listing giving officials until September 11, 2026, to make contact before the group releases the full dataset, a listing the group has labeled a “final warning.” The claimed 200,000-record figure comes directly from the attackers and has not been independently verified or confirmed by the state as of publication.
Part of a Broader Pattern of Government Database Targeting
ShinyHunters has claimed responsibility for a string of high-profile extortion cases against corporate and government targets over the past year, frequently relying on compromised credentials and account takeover rather than novel technical exploits to gain initial access. The alleged Florida incident underscores a recurring weak point in large government record systems: authentication and account-recovery workflows that, once compromised, can expose bulk record access far beyond what a single stolen credential would typically allow.







