Florida Says Attackers Entered Its Driver Database Through a Single Officer's Compromised Personal Account
Florida's FLHSMV confirmed its DAVID driver database was breached by ShinyHunters, attributing access to a Plant City officer's compromised personal credentials — contradicting the gang's own account of a password-reset exploit.
Florida’s Department of Highway Safety and Motor Vehicles confirmed on September 11 that its DAVID driver database was breached by what it called an international cybercriminal organization, making it the second major holder of Americans’ driver’s license information to be compromised that month. The ShinyHunters extortion gang had already claimed responsibility, posting a sample of stolen DAVID records — including one purportedly belonging to Jeffrey Epstein — and setting a September 11 negotiation deadline on its dark-web site.
The agency’s investigation arrived at a different explanation for how the attackers got in than the one ShinyHunters itself had offered publicly. FLHSMV determined that the breach used compromised credentials belonging to a single Plant City Police Department user who had improperly stored them on a personal electronic device. ShinyHunters, by contrast, had claimed it exploited a password-reset vulnerability to access multiple DAVID accounts — a version of events the agency has not corroborated.
FLHSMV has not confirmed the gang’s claim of 200,000 stolen records. The breach was discovered on September 4, and the agency said it is working with Florida law enforcement and the Florida Digital Service, though details about the scope of compromised data remain limited.
What makes the timing especially notable is an Anthropic report released the same day as FLHSMV’s confirmation, which found that suspected ShinyHunters affiliates had been using AI tools to scan for credentials, map unfamiliar systems, and move from a stolen developer token to full administrative access in roughly three hours. Google’s incident responders corroborated the pattern, confirming that ShinyHunters members are actively integrating AI into their attack workflows.
The Plant City credentials detail is a familiar one in breach postmortems: a single set of keys, poorly secured on a personal device, opening access to a statewide law-enforcement database. That the attackers — or at least the organizers attributing the attack to themselves — publicly described a more sophisticated entry method suggests either strategic misdirection or a different path to the same door. Either way, the gap between what FLHSMV says happened and what ShinyHunters claims happened is the kind of discrepancy that tends to narrow once the full forensic picture emerges, though for now the agency is standing by its account.
For a database accessible to every sworn law-enforcement officer in the state, the fact that a single officer’s personal-device hygiene was the attack surface is difficult to frame as reassuring. The investigation is ongoing.