Florida DMV DAVID Database Breach from Stolen Police Login

Florida DMV DAVID Database Breach from Stolen Police Login

Florida officials say a stolen Plant City Police login gave attackers access to the DAVID driver database, but the number of affected records is still unknown.

The Florida DMV has confirmed that its DAVID driver database was breached after an attacker used a stolen police account credential. In a September 4, 2026 statement on X, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) said it learned of the intrusion by an international cybercriminal organization, quickly mitigated it, and found no further breach was ongoing.

FLHSMV's investigation determined that the attacker used compromised login credentials belonging to a single Plant City Police Department user. Those credentials had been improperly stored on the employee's personal electronic device. The agency has notified the Florida Office of the Attorney General and is working with the Florida Digital Service and the Florida Department of Law Enforcement. Because the matter is an ongoing criminal investigation, the agency said further information will be released at an appropriate time.

The confirmation follows a claim by ShinyHunters, a group known for data extortion, that it broke into the DAVID database and stole more than 200,000 driver records. ShinyHunters described a different access path before the agency's announcement. The group said it exploited a password reset flaw to reach multiple DAVID accounts, including accounts used by DMV employees and an FBI agent. The attackers then said they moved through DAVID record IDs and downloaded associated HTML pages and images starting on September 3. As proof, the group shared a screenshot of a DAVID record belonging to Jeffrey Epstein that contained sensitive personal and vehicle information. ShinyHunters later told BleepingComputer that it had lost access to the system and believed the flaw was being patched.

FLHSMV has not said how many records were accessed or stolen, and it has not confirmed the group's claim that more than 200,000 records were taken. The different explanations also leave open questions about the exact route of compromise. A stolen credential stored on a personal device points to a human and device security failure, while a password reset flaw would indicate a weakness in the DAVID web application itself. Either way, a single account can become the entry point to a large database of driver records.

For website owners and IT teams, the lesson is practical. Admin panels, customer portals, and internal systems often rely on the same kind of username-and-password access as the DAVID database. Reusing passwords across services raises the chance that one leaked credential will open another system. Multi-factor authentication (MFA), which requires a second proof beyond a password, can blunt the value of a stolen credential. Storing work passwords on personal phones or laptops also expands the attack surface, because personal devices may not have the same security controls as managed work equipment.

Driver database records are particularly sensitive because they combine identity information with vehicle details, which can be used for targeted fraud or impersonation. Even without confirmation of the total number of records, Florida residents whose information appears in the DAVID database may want to watch for notices from the state and be alert for unusual account activity. A password reset flaw is a weakness in the process that lets a user regain access to an account; if abused, it can let an attacker take over an account without knowing the original password.

For organizations that run similar access portals, reviewing who can log in and where credentials are stored is a practical first step. AEU-I's security-first consulting can help map access and reduce the chance of a single weak login leading to a breach, although disciplined employee handling of passwords remains essential.

How to Protect Yourself

  1. Use a separate, strong password for every work or government account, and never reuse passwords across different websites or services.
  2. Turn on two-factor authentication, which asks for a second code from your phone, for any account that offers it.
  3. Do not keep work or government login details on a personal phone, tablet, or computer unless your employer specifically requires and secures it.
  4. If you receive a notice that your driver or vehicle information may have been exposed, monitor your credit and consider placing a free fraud alert with a credit bureau.
  5. Treat any unexpected password reset or account access message as a warning and report it to your IT team or the service provider.

Terms Explained

  • credential A username and password pair used to prove who you are when logging in to a system.
  • password reset flaw A weakness in the process that lets a user regain access to an account, which an attacker can abuse to take over the account.
  • DAVID The Florida driver and vehicle information database named DAVID that stores driver records.
  • ShinyHunters A cybercriminal group that steals data and then uses it for extortion.
  • multi-factor authentication (MFA) A security method that asks for a second proof, such as a code from your phone, in addition to a password.

Related AEU services

  • AEU-I IT and security consulting
  • AEU Data Cloud and data infrastructure