ShinyHunters Claims Theft of 200,000+ Florida Driver Records From State DMV System

The extortion crew says it abused a password-reset flaw in Florida's law-enforcement lookup tool, DAVID, and posted Jeffrey Epstein's record as proof.

ThreatVectr Newsdesk· 4 min read
A digital lock breaking open over a map of Lithuania, symbolizing a data breach
Share

Key points

  • ShinyHunters, a criminal group that steals data and demands payment, says it broke into Florida's DAVID driver-records system on September 3, 2025.
  • The group claims more than 200,000 driver records were copied, including names, addresses, Social Security numbers and vehicle details.
  • To prove the theft, the criminals published a screenshot of Jeffrey Epstein's DMV file.
  • The way in was a broken password-reset feature that let them take over accounts, allegedly including one belonging to an FBI agent.
  • The same group says more state DMV breaches will be announced in the coming weeks.

The extortion group known as ShinyHunters says it stole more than 200,000 driver records from Florida's Department of Highway Safety and Motor Vehicles (FLHSMV), first reported by BleepingComputer. The target was DAVID, short for Driver and Vehicle Information Database, the internal lookup tool police and state officials use to pull up any Florida driver.

To prove the theft, the criminals posted a screenshot of Jeffrey Epstein's DMV record. It showed his address, Social Security number, date of birth, driver's licence number, and the cars registered in his name.

That is the kind of information identity thieves pay well for.

How did the hackers get in?

They abused a broken password-reset feature. According to ShinyHunters, a flaw in how DAVID handled password resets let them take over accounts that already existed in the system, including accounts belonging to DMV staff and, they claim, an FBI agent.

Once inside, the group says it wrote a simple script that walked through record IDs one by one, downloading the pages and images attached to each driver. The theft began on September 3, 2025. The group told reporters it has since lost access and that the underlying flaw is being patched.

FLHSMV and the FBI have not publicly commented.

What was actually taken?

DAVID holds far more than a name and photo. Each record can include the driver's home address, Social Security number, date of birth, licence number, issue and expiry dates, insurance details, prior vehicles, parking permits, and every past licence transaction.

In short: enough to open credit lines, file fake tax returns, or impersonate someone at a bank.

Detail What we know
Target system DAVID (Driver and Vehicle Information Database), run by FLHSMV
Records claimed stolen Over 200,000
Breach start date September 3, 2025
Entry method Password-reset flaw used to hijack existing accounts
Proof released Jeffrey Epstein's full DMV record

Should Florida drivers be worried?

Yes, cautiously. If the 200,000 figure holds, a slice of Florida drivers now have their Social Security numbers and home addresses in criminal hands. Nothing has been dumped publicly yet: ShinyHunters listed FLHSMV on its leak site and is demanding negotiation first.

Practical steps for Florida drivers: place a free credit freeze with the three US credit bureaus, watch for tax-refund fraud in the next filing season, and be sceptical of any phone call or text claiming to be from the DMV, your bank, or law enforcement asking to "confirm" personal details.

Who are ShinyHunters?

ShinyHunters is a name that has been passed around several criminal crews since 2018. The current operation runs data theft and extortion at scale, and has been tied to breaches at Google, Cisco, PornHub, and Match Group, among others.

Their favourite trick lately is voice phishing, where they ring up an employee, pretend to be IT support, and talk them into typing their password and multi-factor code into a fake login page. That gets them into single sign-on accounts at Okta, Microsoft and Google, and from there into whatever the company runs on Salesforce, Microsoft 365, Slack, or Dropbox.

A source told BleepingComputer the same group is now social-engineering other state DMVs. ShinyHunters confirmed more announcements are coming.

Arrests have been made over the years, including suspects tied to the Snowflake thefts and the PowerSchool breach. The name keeps operating regardless.

© 2026 Threat Vectr