
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as “DAVID” and stole over 200,000 records about drivers in the state.
As proof of the breach, the threat actor has released a screenshot of Jeffrey Epstein’s DMV record, including his address and registered vehicles.
DAVID is the “Driver and Vehicle Information Database” platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver.
“The Driver And Vehicle Information Database (DAVID) is a multifaceted database that affords immediate retrieval of driver and motor vehicle information that is indispensable for law enforcement and criminal justice officials,” reads a description on the FLHSMV website.
“DAVID is the primary reporting mechanism for Fatalities and Serious Bodily Injury (FSBI).”
Last night, ShinyHunters added FLHSMV to its data leak site, warning that it would leak the allegedly stolen data if the agency did not negotiate with them.

As proof of the breach, the threat actors released a screenshot of Jeffrey Epstein’s record in the DAVID system. This record includes the person’s address, Social Security number, birth date, driver’s license ID, issuance and expiration dates, and registered vehicles.
The system also has tabs for additional information, including driver’s license transactions, addresses, insurance, prior vehicles, and parking permits.
ShinyHunters told BleepingComputer they breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system. These accounts allegedly belonged to DMV employees and an FBI agent.
Using this access, the threat actors say they iterated through the records by IDs and then downloaded the associated HTML and images for the drivers. This allegedly allowed them to steal over 200,000 data records since the breach began on September 3rd.
The threat actors told BleepingComputer that they have since lost access to the database and that the password-reset flaw used to compromise accounts is being patched.
BleepingComputer contacted FLHSMV and the FBI yesterday about the incident and will update the story if we receive a response.
A source told BleepingComputer that the threat actors are also targeting other states’ DMV platforms using social engineering attacks.
When asked whether they are targeting additional DMVs, ShinyHunters told BleepingComputer they expect to announce other breaches over the coming weeks.
Who is ShinyHunters
ShinyHunters is an extortion gang known for targeting online web applications and cloud SaaS environments in data theft attacks.
The name ShinyHunters has long been associated with numerous threat actors who have conducted data breaches since 2018.
Over the past year, threat actors using the ShinyHunters name have become one of the most prolific groups that conduct data theft and extortion attacks against companies worldwide.
Initially focusing on Salesforce and other cloud SaaS environments, the threat actors are linked to a growing number of breaches involving companies such as Google, Cisco, PornHub, and online dating giant Match Group.
The extortion gang commonly breaches third-party integration companies and uses stolen authentication tokens to access connected SaaS environments and steal customer data.
More recently, the threat actors have been conducting voice phishing (vishing) attacks targeting Okta, Microsoft, and Google single sign-on (SSO) accounts, where they impersonate IT support staff to trick employees into entering credentials and multi-factor authentication (MFA) codes on phishing sites.
As BleepingComputer first reported, the ShinyHunters group has also adopted device code vishing attacks to obtain Microsoft account authentication tokens.
After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
The extortion gang was also behind a massive data-theft attack on Instructure Canvas in May that caused significant outages to the platform. The company eventually reached an “agreement” with the threat actors to prevent the data stolen in a recent breach from being leaked online.
Over the years, numerous arrests have been linked to the ShinyHunters name, including suspects connected to the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.
However, even with these arrests, threat actors using the ShinyHunters name remain a threat to enterprises worldwide.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
