ShinyHunters published hundreds of thousands of files stolen from Florida’s DAVID system after the victim did not pay a ransom or cooperate with the group’s demands, according to TechCrunch. DAVID is a Florida state database leak holding driver and vehicle records used by government agencies and law enforcement.
The published files include names, addresses, vehicle identification numbers, and, in a smaller subset, Social Security numbers and immigration documents. The data is already publicly accessible, meaning identity theft and fraud risk is active, not theoretical.
Florida’s Highway Safety and Motor Vehicles agency (FLHSMV) confirmed the breach and traced it to a police officer’s credentials stored on a personal device, per TechCrunch. The figure of over 200,000 affected records originates from hacker claims reported by BleepingComputer, not a verified state count.
What Was Taken
The stolen files range from vehicle ownership certificates to immigration documents, with Social Security numbers present in a smaller portion of the records.
Vehicle ownership certificates in the breach contained buyers’ and sellers’ names and addresses alongside VINs, according to TechCrunch.
A smaller number of files also held Social Security numbers and government-issued documents, including non-U.S. passports and immigration papers. Driver’s licenses and photos do not appear to have been included, per TechCrunch.
Hackers posted a screenshot they claimed showed a record associated with Jeffrey Epstein, according to TechCrunch. That claim originates with ShinyHunters and has not been independently verified.
BleepingComputer reported that ShinyHunters claimed to have exploited a password-reset flaw to compromise multiple accounts within the system. The alleged theft began around September 3, according to BleepingComputer.
FLHSMV told NBC News the breach was conducted by an “international cybercriminal organization.” The agency stated the incident has been contained.
Access was traced to a single police officer’s credentials stored on a personal device, per TechCrunch. A single set of credentials, kept off a secured agency device, reportedly unlocked a surveillance app-era risk: a database built to serve law enforcement across the state.
What Florida’s Agency Said
FLHSMV has confirmed the breach and described it as contained, but has not disclosed a definitive record count or a notification plan.
FLHSMV confirmed the breach last week, described the attackers as an international cybercriminal organization, and said the incident is contained, per NBC News. The agency has not published a definitive record count or announced a public notification plan.
The figures circulating, including the over-200,000 record claim, come from hacker statements reported by BleepingComputer and TechCrunch, not official state tallies. The true scope of exposure remains unclear.
What Affected Floridians Should Know
If your information appears in Florida vehicle or title records, that data may now be publicly accessible and your fraud risk is immediate.
If your name appears in Florida vehicle ownership or title records, your personal information may now be publicly accessible. That exposure could include your address, purchase history, and in some cases your Social Security number or immigration documents.
The state has not announced a notification process or confirmed exactly how many people are affected. Placing a fraud alert with the major credit bureaus is a reasonable first step. Monitoring accounts for unusual activity is equally advisable while official guidance remains absent; knowing how to stay safe from common digital threats is a useful complement to any response. The FTC’s IdentityTheft.gov offers specific instructions for responding to a data breach.
Watch for further statements from FLHSMV as the agency’s response develops.




























