Skip to content
vulnerabilityransomwarecredential-theft

ShinyHunters claims 200K records from Florida's law-enforcement DMV database, sets September 11 deadline

3 min read
Share

The ShinyHunters extortion group listed the Florida Department of Highway Safety and Motor Vehicles on its data leak site on September 7, 2026. The group claims to have exfiltrated more than 200,000 records from DAVID, the Driver and Vehicle Information Database, and posted a screenshot of a named individual's DMV record as proof of access. A September 11 deadline has been set, after which the group says it will publish the data.

What DAVID is and why it matters

DAVID is not a standard public-facing database. It is a restricted law-enforcement system that gives authorized government and law enforcement users access to driver records, vehicle registrations, and personal identification details. Data in DAVID supports criminal investigations, background checks, and regulatory enforcement. If the breach is confirmed, the affected records are not just personal data: they are records that law enforcement agencies rely on operationally. A 200,000-record DAVID exposure has a different risk profile than a standard consumer e-commerce breach.

What ShinyHunters says happened

According to the group's statement to BleepingComputer, the exfiltration began around September 3, 2026. ShinyHunters says it pulled the records before losing access, attributing the loss of access to the underlying flaw being patched mid-operation. The Florida DHSMV has not confirmed any breach or cyberattack. This is typical in active extortion situations: the affected organization says as little as possible while investigating and assessing its legal obligations.

The extortion playbook

ShinyHunters has used this pattern repeatedly: post a credible proof sample, set a short deadline, and wait for contact or payment. The Epstein record screenshot serves a specific function as a high-salience proof item that generates press coverage and increases pressure on the target. The September 11 deadline is tight enough to be coercive but long enough to allow a response. If Florida DHSMV does not make contact by then, expect a staged data release.

What to watch

Watch September 11 for whether data is published or the deadline is extended. A published dataset from DAVID is particularly dangerous if it enables correlation with other government or law-enforcement datasets that have leaked previously. Identity thieves and social engineers targeting public-sector employees would have immediate use for this data. If the breach is confirmed, Florida's data breach notification statute will require individual notifications.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your organization is managing incident response or breach notification obligations for a government or public-sector breach.