Hackers Broke Into Florida's Law Enforcement Driver Database and Stole 200,000 Records
ShinyHunters exploited a password-reset flaw to steal 200K Florida driver records — SSNs, photos, addresses — and set a Sept. 11 deadline to publish them.
What Just Got Stolen, and Why It Matters to You
On September 7, 2026, the hacking group ShinyHunters posted Florida's law enforcement driver database on their dark-web extortion site. They're demanding the state make contact by September 11. If no one responds, the data goes public.
That's not a distant corporate breach. If you've ever held a Florida driver's license, your file may be in that database.
What Is DAVID?
DAVID stands for Driver and Vehicle Information Database. Florida law enforcement agencies use it daily to look up driver records, check vehicle histories, verify insurance, and pull personal identifying information during investigations and traffic stops. It's a secured system, not a public-facing portal. It was never meant for civilians to access. That's part of what makes a breach here so damaging.
How Did Attackers Get In?
The attackers didn't crack an encryption key or write sophisticated malware. They exploited a password-reset flaw.
A password-reset flaw means the process a system uses to let someone reclaim their account can be manipulated to let an attacker claim someone else's account instead. It's a well-known class of vulnerability, and it's often straightforward to exploit when it exists.
ShinyHunters used this flaw to hijack multiple accounts, including accounts belonging to DMV employees and, reportedly, an FBI agent. Once inside legitimate accounts, they had authorized-looking access to the database. No alarm went off. No one blocked them at the door.
Exfiltration started around September 3, 2026. By the time the flaw was patched and the attackers lost access, they had already pulled over 200,000 records.
What Data Was Stolen?
The stolen records reportedly include:
- Full legal name
- Home address
- Social Security number
- Date of birth
- Driver's license photo
- Signature
- Vehicle registration details
That is not just a data leak. That is a complete identity theft kit. Your SSN opens credit accounts. Your photo and signature defeat document verification. Your address tells someone where you live. Your vehicle registration ties your identity to a physical object that moves through the world.
Identity thieves often succeed with three or four pieces of your information. This breach hands them all seven at once.
Where Does the Breach Stand Right Now?
As of September 8, 2026, the Florida Department of Highway Safety and Motor Vehicles had not publicly confirmed or denied the breach. ShinyHunters' deadline is September 11. That is a live, ticking window.
The state's silence is not reassurance. It may mean they're verifying the scope, preparing a statement, or managing the situation internally. It doesn't mean the data is safe.
What Should You Do Right Now?
You don't need to wait for an official statement to protect yourself. You can act today.
-
Freeze your credit at all three bureaus. Go directly to Equifax, Experian, and TransUnion and place a security freeze. This is free. It blocks new credit lines from being opened in your name without your explicit approval, even if someone has your SSN.
-
Freeze your credit with NCTUE and ChexSystems too. These specialty bureaus cover utility accounts and bank accounts. They're less well-known and often overlooked.
-
Check your existing accounts for unusual activity. Log in to your bank and credit card accounts. Look for anything unfamiliar. Set up transaction alerts if you haven't already.
-
Watch for phishing attempts. Attackers who hold your name, address, and date of birth will craft convincing emails, texts, and phone calls. If someone contacts you about an account, hang up and call back using a number from the official website.
-
Enable the strongest authentication your accounts support. If a service offers a passkey or hardware security key, use it. If not, use an authenticator app over SMS. SMS-based codes can be intercepted.
-
Consider a data removal service. Your personal information also sits in data broker databases. Services like DeleteMe or Mozilla Monitor Plus can help remove it from brokers that sell it to anyone who asks.
-
Pull your free annual credit reports. Visit AnnualCreditReport.com and request reports from all three bureaus. Look for accounts or inquiries you don't recognize.
The Real Problem Underneath This Breach
A password-reset flaw shouldn't be able to unlock a law enforcement database holding 200,000 people's Social Security numbers. The fact that it did points to a gap between how sensitive the data is and how seriously it was protected.
Government databases often hold the most sensitive records that exist about you. They are also sometimes among the least well-funded for security. That combination creates risk for everyone whose data sits inside them, which is to say, almost everyone.
You didn't choose to be in DAVID. If you've driven in Florida, you were entered automatically. You had no say in how it was secured, and you have no way to remove yourself from it. What you can control is how well-defended your identity is if that data surfaces publicly on September 11.
Do this now:
- Freeze your credit at Equifax, Experian, TransUnion, NCTUE, and ChexSystems (free, takes about 15 minutes total)
- Set up transaction alerts on your bank and credit card accounts
- Switch to an authenticator app for two-factor authentication wherever you can
- Watch for suspicious contact from anyone who already knows your personal details
Sources
Common Questions About Breach
What should I do immediately after a data breach?
Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.
How long do companies have to notify me after a data breach?
In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.
Should I freeze my credit after a data breach?
Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.
More in breach
Stay invisible. Follow @hack_decoded