Most of us hand over a lot of personal information to the DMV because we have no choice. Your address, birth date, driver’s license information and other identifying details can all end up in government systems. That is why a breach involving driver records deserves attention.

Florida officials have now confirmed that the Florida Department of Highway Safety and Motor Vehicles, or FLHSMV, experienced a data breach. The agency says it learned about the incident on Sept. 4, quickly mitigated it and has seen no further breach or ongoing unauthorized access.

The confirmation follows claims from the ShinyHunters extortion group that it accessed Florida’s Driver and Vehicle Information Database, known as DAVID, and stole more than 200,000 driver records.

Florida has not confirmed that record count or publicly said exactly what information was taken. Here’s what ShinyHunters claims happened, what Florida says its investigation found and what drivers should do now.

INSURANCE BREACH EXPOSES 7M DRIVER’S LICENSES

NEW! Join our upcoming CyberGuy LIVE class: Get Better Health Care With AI

In this free live online class, Kurt “CyberGuy” Knutsson will show you five practical ways AI can help you take a more active role in your health care. You’ll learn how to organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare questions for your next doctor’s visit. No technical

experience is needed.

Register for free now at CyberGuyLive.com

FLHSMV says its investigation traced the breach to credentials belonging to a single Plant City Police Department user. According to the agency, those credentials were improperly stored on the employee’s personal electronic device. A criminal actor was then able to take advantage of them.

That explanation gives us the first official account of how the breach occurred. It also differs from the access method ShinyHunters previously described.

FLHSMV says it notified the Florida Office of the Attorney General as required under state law. The agency is also working with the Florida Digital Service and Florida Department of Law Enforcement. The criminal investigation remains ongoing. Officials say additional information will be released at an appropriate time.

ShinyHunters says it stole more than 200,000 driver records from DAVID. BleepingComputer reported that the group provided a screenshot of a DAVID record belonging to Jeffrey Epstein as evidence that it had accessed the system. The screenshot reportedly contained an address, Social Security number, birth date, driver’s license information and registered vehicle details.

DAVID can contain far more than a person’s basic driver’s license information. Government records describing the system show that authorized users may have access to driver information, photographs, signatures, vehicle history, insurance information and other identifying records.

However, FLHSMV still has not disclosed how many records were accessed or stolen. The agency also has not confirmed ShinyHunters’ claim that more than 200,000 records were taken.

CyberGuy reached out to FLHSMV for additional comment, but did not hear back before our deadline.

ShinyHunters originally told BleepingComputer that it breached DAVID through a password-reset flaw. The group claimed that weakness allowed it to compromise multiple accounts, allegedly including accounts belonging to DMV employees and an FBI agent. ShinyHunters said it then moved through DAVID record IDs and downloaded associated pages and driver files beginning Sept. 3. The group later said it had lost access and believed the password-reset issue was being patched.

Florida’s investigation now points somewhere else. FLHSMV says the attacker took advantage of credentials belonging to one Plant City Police Department user that had been improperly stored on a personal electronic device. The agency has not backed ShinyHunters’ claim that a password-reset flaw allowed the group to compromise multiple accounts. So, for now, the password-reset explanation remains ShinyHunters’ version of events, while compromised police credentials are the access method Florida has publicly identified.

DAVID serves authorized government users rather than ordinary public searches. FLHSMV says its Bureau of Records manages access to driver records through DAVID for law enforcement and other approved entities. The agency also audits users for compliance.

Florida policy treats personal information in motor vehicle records as confidential. That information can include Social Security numbers, driver identification numbers, addresses and medical or disability information. That kind of information can give criminals powerful material for identity theft.

Imagine getting a call from someone claiming to represent a government agency. The caller already knows your address, birth date and driver’s license information. Suddenly, the scam sounds far more convincing.

IS YOUR SOCIAL SECURITY NUMBER ON THE DARK WEB?

BleepingComputer previously reported that a source said the attackers were targeting DMV platforms in other states through social engineering. ShinyHunters also told the outlet it expected additional DMV breaches to surface.

There has been no confirmation from Florida that the current breach involved other state DMV systems. Still, the possibility deserves attention because state motor vehicle agencies hold information that can be extremely valuable for identity fraud and targeted scams.

If criminals find a technique that works against one government system, they often look for similar access elsewhere.

ShinyHunters is an extortion operation associated with data theft attacks against companies and online services.

Threat actors using the name have been linked to attacks involving Salesforce environments and companies including Google, Cisco and Match Group.

More recently, the attackers have used voice phishing, also called vishing. In these attacks, someone impersonates IT support and tries to convince an employee to enter credentials or authentication codes into a phishing site.

The attackers have also targeted single sign-on accounts connected to services such as Microsoft 365, Google Workspace and Salesforce.

FLHSMV referred to the attacker in its statement only as an “international cybercriminal organization.” The agency did not publicly identify ShinyHunters by name. So, while ShinyHunters has claimed responsibility and Florida has confirmed a breach, Florida has not publicly attributed the attack to the group.

Still, this shows why protecting trusted accounts has become so important. Once an attacker gets legitimate credentials, other connected services may become accessible too.

You do not need to wait for a confirmed case of identity theft before protecting yourself. These steps can make stolen personal information harder for criminals to use.

A credit freeze can make it harder for someone to open new credit accounts in your name. You need to place a freeze separately with Equifax, Experian and TransUnion. Credit freezes are free. You can temporarily lift one when you legitimately need a lender to access your credit.

Check your credit reports for new accounts or inquiries you do not recognize. You can request your reports through AnnualCreditReport.com, the federally authorized source for free credit reports. Also keep an eye on your financial accounts. Small unfamiliar transactions can sometimes be an early warning sign.

A confirmed breach creates a ready-made lure for scammers. You could receive a text, email or phone call claiming your Florida driver information was exposed. Be especially careful if the sender pressures you to verify personal information or click a link. Instead, visit FLHSMV through its official website at flhsmv.gov/ yourself.

FAKE SHINYHUNTERS SEXTORTION EMAIL USES CARNIVAL BREACH DATA

Scammers may use news of a DMV breach to send fake alerts containing malicious links or attachments. Strong antivirus software can help detect malware, phishing sites and other threats before they compromise your device or personal information. Keep your antivirus software running and updated on your computers and mobile devices. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Your primary email account deserves extra attention because criminals can use it to reset passwords for other services. Give it a strong, unique password and use a password manager to create and securely store it. Then turn on multifactor authentication. Whenever possible, consider an authenticator app or passkey rather than relying only on codes sent by text message.

Review bank accounts, credit cards and other important services for activity you do not recognize. Also pay attention to unexpected government correspondence. A strange tax notice or benefits letter could signal that someone has used your identity.

You may also want to consider an identity theft protection service that monitors for suspicious use of your personal information and can help with recovery if your identity is stolen. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com

If you discover identity theft, report it at IdentityTheft.gov and follow the recovery steps provided by the Federal Trade Commission.

Data brokers and people-search websites can provide scammers with even more information about you. Removing that data cannot erase records stolen during a breach. However, reducing the information available elsewhere can make it harder for criminals to build a detailed profile and create convincing scams.

Consider using a personal data removal service to help find your information on data broker sites and submit removal requests on your behalf. These services can also keep checking for information that reappears over time. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Now that FLHSMV has confirmed the breach, scammers could imitate any future notices sent to affected drivers. FLHSMV has not yet publicly disclosed how many people were affected or exactly what information was taken. Do not automatically trust an email simply because it mentions DAVID or the Florida DMV. Avoid using links in unexpected messages. Go directly to the agency’s official website to verify any notice.

Florida has now confirmed the breach, but some of the biggest questions remain unanswered. ShinyHunters claims it stole more than 200,000 driver records, while Florida says the attacker got in using credentials belonging to a Plant City Police Department user that were improperly stored on a personal device. What we still do not know is exactly how much information was taken or whose records were exposed. Until Florida releases more details, I would take this seriously. Check your credit, lock down your important accounts and be especially suspicious of unexpected DMV texts, emails or calls asking you to verify personal information.

If hackers stole your driver’s license record, Social Security number and address from a government database, how quickly would you expect the state to tell you? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.