Florida’s driver database was breached, then published
A police officer’s stolen login opened DAVID, the database Florida police use to look up drivers. The state would not pay, so the files went public. Here is what FLHSMV has confirmed, what the leak holds, and what to do if you drive or own a car in Florida.
In early September 2026 the ShinyHunters group got into DAVID, Florida’s driver and vehicle database, using one Plant City Police Department user’s credentials stored on a personal device. FLHSMV confirmed the breach, did not pay, and the group published about 595,000 files by 14 September: mostly vehicle ownership certificates with names, addresses and VINs, plus records with Social Security numbers and scans of passports and immigration documents. There is no official count and no lookup yet. Freeze your credit, get an IRS Identity Protection PIN, and treat any call or text that quotes your vehicle details as a scam.
What happened, in order
Two weeks from the break-in to a public archive. The agency’s own statements and the group’s posts disagree on several points, and the table after this one sets those out side by side.
| When | What happened |
|---|---|
| 3–4 September 2026 | Someone signs in to DAVID, the Driver and Vehicle Information Database run by the Florida Department of Highway Safety and Motor Vehicles (FLHSMV), and pulls records one ID at a time. The agency says it detected the activity on 4 September and shut it down. |
| 7 September | ShinyHunters list “State of Florida DMV” on their leak site with a final warning and a deadline of 11 September. As proof they post a screenshot of a single DAVID record: Jeffrey Epstein’s, showing his address, Social Security number and registered vehicles. |
| 8 September | BleepingComputer, Cybernews and others report the claim: more than 200,000 driver records, taken through what the group calls a password-reset flaw. |
| By 11 September | FLHSMV confirms a breach and gives a different account of the way in: the login of one Plant City Police Department user, stored improperly on that employee’s personal device. It has notified the Florida Attorney General and is working with the Florida Department of Law Enforcement and the Florida Digital Service. |
| 11 September | The deadline passes. The state does not pay. |
| 14 September | ShinyHunters publish a downloadable archive. Straight Arrow News counts 594,701 files in it: 475,207 images and 119,494 driving-record pages. |
| 16 September | TechCrunch reviews a copy and describes hundreds of thousands of vehicle ownership certificates, a smaller set of records with Social Security numbers, and scans of foreign passports and immigration papers. Local reporting the same day says the agency will notify the Floridians whose data was taken. |
What is confirmed, and what is only claimed
The 200,000 figure comes from the group, and so does the password-reset story. The police login, the notice to the Attorney General and the promise of letters come from FLHSMV. The contents of the archive come from two newsrooms that looked at it.
| Question | Confirmed or independently reviewed | What ShinyHunters claimed |
|---|---|---|
| How they got in | FLHSMV: the credentials of a single Plant City Police Department user, kept on that employee’s personal device rather than an agency one. | A password-reset flaw that let the group take over several accounts, which it says belonged to DMV staff and an FBI agent. |
| How many people | No official count. FLHSMV has not published one and says more information will follow. | More than 200,000 driver records. |
| What was published | An archive of roughly 595,000 files, examined separately by Straight Arrow News and TechCrunch. Vehicle ownership certificates make up the bulk of what TechCrunch saw. | Records pulled from DAVID by stepping through record IDs and saving each page and its images. |
| What the files hold | Names, home addresses and vehicle identification numbers throughout; Social Security numbers in a smaller part of the set; scans of non-US passports, green cards, visas and work permits. Straight Arrow News also describes license photos, signatures and Social Security cards. TechCrunch did not find license photos in the copy it reviewed. | Full DAVID records. The group’s proof screenshot showed Social Security number, date of birth, license number, issue and expiry dates, vehicles, insurance, prior addresses and parking permits. |
| Whether access continues | FLHSMV says the intrusion was mitigated quickly and nothing further is ongoing. | The group told BleepingComputer it lost access and that the flaw was being patched. |
| Other states | Nothing confirmed. | ShinyHunters said they planned to name breaches at other state motor vehicle systems in the following weeks. |
| Letters to drivers | None yet. The agency has told the Attorney General, as Florida law requires, and says it will notify the people involved. The Florida Information Protection Act gives 30 days from the point a breach is determined, with 15 more available for good cause. | Not applicable. |
Sources: BleepingComputer, Cybernews and CyberInsider, 8 September 2026; FLHSMV’s statement as reported by Hoodline and Florida Politics, 11 September 2026; Straight Arrow News, 14 September 2026; TechCrunch and WWSB, 16 September 2026. FLHSMV has not published a count of the people involved.
1. What DAVID is, and why one login was enough
DAVID is the database Florida police use at a traffic stop. It pulls a driver’s license record, photo and signature, address history, registered vehicles, insurance and license transactions onto one screen, and it is built to be reached from patrol cars and station desks across the state. That design means logins are held by a great many people in a great many agencies, and the security of the whole system depends on each of them. By the agency’s own account, the break-in did not need a flaw in DAVID at all: it used one Plant City Police Department user’s credentials that had been kept on a personal device. ShinyHunters tell a more technical story, about a password-reset weakness and several hijacked accounts. The agency’s version is the one on the record, and it is also the less comforting one, because a stolen login is a much easier thing to repeat than a software bug.
2. What is in the published files
Two outlets have gone through the archive and described it a little differently. TechCrunch saw mostly vehicle ownership certificates, hundreds of thousands of them, each with the owner’s name, home address and the vehicle identification number, plus a smaller set of records with Social Security numbers and scans of non-US passports and immigration papers. Straight Arrow News counted 594,701 files and described passport scans going back to the 1990s, Social Security cards, permanent resident cards, visas, work permits, vehicle titles, and license photos with signatures. TechCrunch specifically did not find license photos in its copy. Until FLHSMV says what was taken, the careful reading is that the name, address and vehicle details are out for a large group, and more sensitive documents for a smaller one.
3. The honest answer to “am I in it”
There is no way to check yourself today. The archive sits on a criminal leak site, not in any service that indexes breaches, and those services work from email addresses, which a vehicle certificate does not carry. The answer will come from FLHSMV’s letter, which the agency says it will send and which Florida law expects within about a month and a half at most. Until then, the useful question is simpler: do you hold a Florida license, or have you titled a vehicle in Florida? If yes, you are in the population the records were drawn from, and the steps below are cheap enough that it makes sense to take them now rather than wait to find out.
4. What Florida drivers should do this week
Freeze your credit at Equifax, Experian and TransUnion; it is free, and it is the one step that stops an account being opened rather than telling you afterwards. Request an Identity Protection PIN from the IRS, since a name, address and Social Security number are what a fraudulent tax return needs. If you have not created a my Social Security account at ssa.gov, create one before someone else does it with your number. Ask FLHSMV, or the county tax collector’s office that handles your licensing, whether a duplicate license or a duplicate title has been issued in your name. And if something has already been opened in your name, start at identitytheft.gov: the report it produces is what banks, the IRS and the credit bureaus will ask for.
5. The calls and texts that come next
A stolen vehicle certificate is more useful to a scammer than it looks, because the VIN and plate are details people assume only the state knows. Expect calls and texts that recite them: a registration about to be suspended, a title problem, an unpaid toll, a fine that has to be settled today. Florida drivers were already getting fake toll texts before this, and a message that includes your real vehicle details will be far more convincing. FLHSMV does not collect payments by phone or by text link. Later there will be a second wave about a settlement or compensation, asking for bank details to release money. Nobody legitimate asks for that before a court has approved anything.
6. If you showed a passport or green card to get your license
Non-citizens who got a Florida license or ID had to show a foreign passport, a green card, a visa or a work permit, and both outlets found scans of exactly those documents in the archive. That group tends to get the least attention in coverage and has the most specific risk: calls from people claiming to be immigration officials, quoting a real document number, saying there is a problem with your status that a fee will fix. US immigration authorities do not ask for payment over the phone or by gift card. If you are in this group, keep copies of your documents somewhere safe, report any misuse of a green card or work permit to the issuing agency, and treat any unexpected call about your status as a scam until you have checked it yourself.
7. The part that outlives the breach
A name and home address were never the secret part of a driver record. Florida’s motor vehicle agency has for years sold driver data to businesses under the exceptions federal law allows, and people-search and data-broker sites publish addresses, relatives and phone numbers built from records like these. What the leak adds is certainty: a stranger can now match a document to a current address. Taking down the broker listings is the step on this page with an effect beyond this news cycle, and it has to be repeated, because listings come back. The general order of things after any breach is in our post-breach guide, and the “pay or leak” hub tracks the other organisations this group has named.
Your address was published long before this
The name and address on a vehicle certificate are already listed, with your relatives and phone number, on 499 broker and people-search sites. PersProtect finds where you appear, files the removals and keeps checking. The scan is free.
Check my exposure — free →The Florida DMV breach, answered
Was my Florida driver’s license data stolen?
Nobody can answer that for an individual yet, including FLHSMV, which has not published a count. What is known is the shape of it: the attacker pulled records from DAVID for a few days in early September, the group says it took more than 200,000, and the files it published are mostly vehicle ownership certificates with names, addresses and VINs, with Social Security numbers in a smaller part of the set. If you hold a Florida license or have titled a vehicle in the state, you are in the population it was drawn from. That is not the same as being in it, but the protective steps are cheap enough to take either way.
How will I find out if I am affected?
By letter from FLHSMV, which says it will notify the people whose data was taken. Florida’s breach law gives 30 days from the point a breach is determined, plus 15 days for good cause, so that letter could arrive in October. When it does, check it against flhsmv.gov rather than calling a number printed in it. There is no lookup tool, and this is not the kind of leak that appears in public breach databases, which are built around email addresses. A site that asks you to upload your license to see whether your license leaked is asking for the thing you are worried about.
Is this the same as the IDScan.net breach?
No. They landed in the same fortnight and both involve driver’s licenses, which makes them easy to blur. IDScan.net is a private identity-verification vendor whose scanners sit at rental desks, bars and bank counters; it confirmed its own breach on 10 September after a dark-web service sold lookups into its scans. The Florida incident is a state government database reached with a police login. ShinyHunters themselves said the Florida claim was separate. A Florida driver could, in principle, be in both.
Can I get a new Florida driver’s license number?
Not in the way you can change a password. Florida license numbers are generated from your name and date of birth, which is why a replacement card carries the same number. What is worth doing is asking FLHSMV, or your county tax collector’s office where it handles licensing, whether a duplicate license or a duplicate vehicle title has been issued in your name. That question catches actual misuse, which a new number would not.
Did Florida pay the ransom?
No. The state did not reach an agreement with the group before the 11 September deadline, and ShinyHunters published the archive by 14 September with a note blaming the state for not paying. Paying would not have bought much anyway. A group that holds a copy of the data still holds it after the payment, and the only thing on offer is a promise from the people who took it.
What is DAVID?
The Driver and Vehicle Information Database, FLHSMV’s lookup system for police, courts and other authorized agencies. One screen brings together a driver’s license record, photo and signature, address history, vehicles, insurance and license transactions. It exists so an officer at a traffic stop can confirm who they are talking to, which is why logins are spread widely across Florida law enforcement, and why a single officer’s login on a personal phone was enough to reach it.
My record would only have my address and VIN. Is a credit freeze still worth it?
Yes. The published set mixes vehicle certificates with records that carry Social Security numbers, and nobody outside the agency can tell you which kind yours is. A freeze at Equifax, Experian and TransUnion is free, takes a few minutes each, and stops new credit being opened whoever is asking. If your record turns out to be only a vehicle certificate, the freeze has cost you nothing. If it is one of the others, it is the step that matters most.
Someone called about my registration and knew my VIN. Is that FLHSMV?
Assume not. A caller who reads out your plate or your vehicle identification number sounds official, and this breach just handed that detail to anyone who downloads the archive. FLHSMV does not take payments over the phone to clear a suspended registration or a license problem. Hang up, then check your status yourself at flhsmv.gov or with your county tax collector. The same goes for texts about unpaid tolls, which were already a Florida scam before any of this.
The state can’t take the files back
You can shrink what is published next to them. See which sites list your name, address and relatives right now — free, in about a minute.
Run my free exposure scan →