Florida Department of Highway Safety and Motor Vehicles Data Breach Exposes Driver’s License and Vehicle Records

Published: 12 September 2026
Other Commercial data breach illustration
Breach Discovery: September 2026Breach Notification: September 2026

The Florida Department of Highway Safety and Motor Vehicles confirmed in September 2026 that its DAVID driver database was breached using stolen login credentials from a Plant City police officer. Hackers known as ShinyHunters claim to have taken over 200,000 driver records, though the agency hasn’t verified that number. Affected individuals should monitor credit reports and consider a credit freeze immediately.

CompanyFlorida Department of Highway Safety and Motor Vehicles
IndustryOther Commercial
Data Types ExposedFull Names, Driver’s License Numbers, Dates of Birth, Home Addresses, Vehicle Registration Details, Photographs
People AffectedNot Publicly Disclosed
Attack MethodStolen Credentials
Regulators NotifiedDelaware Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Florida DMV Data Breach?

The Florida Department of Highway Safety and Motor Vehicles has confirmed a data breach involving its DAVID driver database. The agency says unauthorized access to its network occurred in September 2026. This confirmation followed public claims from an extortion group calling itself ShinyHunters, which said it had broken into the system and pulled sensitive driver information.

According to the agency, the breach happened because someone stole login credentials tied to a single Plant City Police Department employee. That employee had reportedly stored the credentials improperly on a personal device. As a result, the attacker was able to log into the DAVID system using a legitimate, trusted account rather than exploiting a flaw in the software itself.

Interestingly, this explanation conflicts with what ShinyHunters originally claimed. The group said it took advantage of a password reset weakness to access multiple DAVID accounts, including ones belonging to DMV staff and even an FBI agent. The hackers claimed they then systematically pulled record after record starting around September 3, 2026, and shared a screenshot of a record linked to Jeffrey Epstein as proof.

Once the Florida DMV learned of the intrusion, it says it moved quickly to contain the incident. The agency stated that the breach was mitigated and that no further unauthorized activity has occurred since. Because this remains an active criminal investigation, the department has not released full technical details about how the intrusion was ultimately stopped.

In response to the incident, the agency brought in additional state resources to assist with its investigation. It is now working alongside the Florida Digital Service and the Florida Department of Law Enforcement. This layered response suggests investigators are still working to determine the full scope of what data was accessed and how.

Who was affected?

The Florida DMV has not publicly disclosed a confirmed number of individuals affected by this breach. ShinyHunters claimed that more than 200,000 driver records were taken from the DAVID system, but the agency has not verified this figure. Therefore, the true scale of the breach remains unclear at this time.

Because the DAVID system is used broadly by Florida law enforcement and government agencies to look up driver and vehicle information, the population affected could include ordinary Florida drivers whose records sit in the database. Additionally, the attackers reportedly accessed accounts belonging to DMV staff and law enforcement personnel, meaning employees themselves may also be impacted.

Given that DAVID houses driver’s license data tied to essentially any Florida resident with a driver’s license or state ID, the potential population is large. However, until the agency releases a confirmed count, affected individuals cannot know for certain whether their specific record was accessed.

What Information Was Potentially Exposed?

The DAVID database is designed to store detailed driver and vehicle records used by law enforcement and government agencies. Based on the ShinyHunters screenshot shared as proof, the exposed data appears to include personal identifying details along with vehicle registration information.

While the Florida DMV has not released a full itemized list, the following categories of information are understood to be at risk based on the nature of the DAVID system and the leaked sample record:

  • Full names
  • Driver’s license numbers
  • Dates of birth
  • Home addresses
  • Vehicle registration details
  • Photographs associated with driver’s license records

If this information fell into the wrong hands, affected individuals could face a heightened risk of identity theft. Driver’s license numbers, combined with a name and date of birth, give criminals enough to open fraudulent accounts or file false tax returns in someone else’s name.

In addition, because DAVID records include home addresses and photos, there is also a risk of targeted scams or impersonation. For example, a scammer could use a stolen driver’s license image to create fake identification documents. This makes vigilance especially important for anyone who suspects their record may have been part of this breach.

What is the company doing?

Once the Florida DMV discovered the intrusion, it says it acted to shut down the unauthorized access and confirmed no further breach activity has occurred. The agency also notified the Florida Office of the Attorney General as part of its legal obligations following the discovery.

In addition to notifying Florida’s Attorney General, the Florida Department of Highway Safety and Motor Vehicles has also filed a formal data breach notification with the Delaware Attorney General. This step reflects the agency’s effort to comply with breach notification requirements across jurisdictions where affected individuals may reside.

Because the investigation remains ongoing, the agency has said it will share more details when appropriate. For now, the Florida Department of Law Enforcement and the Florida Digital Service continue to assist with the technical and criminal aspects of the case. This multi-agency approach suggests the state is treating the incident seriously given the sensitivity of DMV data.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Anyone who believes their information may have been included in this breach should start checking their credit reports regularly. You can request free reports from all three major credit bureaus and review them for unfamiliar accounts or inquiries.

Because driver’s license numbers can be used to open new lines of credit, watching your reports closely gives you the best chance to catch fraud early. If you notice anything suspicious, report it immediately to the credit bureau and consider disputing the entry right away.

Consider a Fraud Alert or Credit Freeze

Given that this breach may involve driver’s license numbers and personal identifying details, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires lenders to take extra steps to verify your identity before approving new credit.

For even stronger protection, you can request a credit freeze, which blocks most new accounts from being opened in your name entirely. This step is free and can be lifted temporarily whenever you need to apply for credit yourself.

Stay Alert for Phishing Attempts

Because stolen personal data is often used to craft convincing scam messages, affected individuals should watch for unexpected emails, texts, or calls claiming to be from the DMV or other government agencies. Scammers frequently use real details from breaches to make their messages seem legitimate.

As a result, you should never click links or share personal information in response to unsolicited messages. Instead, contact the agency directly using a phone number or website you already know is authentic.

Protect Your Driver’s License Identity

If your driver’s license number was exposed, consider contacting the Florida DMV to ask about options for monitoring or flagging your license record for suspicious activity. Some states offer additional verification steps for residents concerned about identity misuse tied to license numbers.

In addition, keep an eye out for notices about unfamiliar vehicles registered in your name or unexpected traffic citations. These can be early warning signs that someone else is using your identity.

Know Your Legal Options

Individuals affected by this breach may have legal options worth exploring, especially if they experience direct financial harm as a result. Consulting with a data breach attorney can help you understand whether you qualify for compensation.

Many attorneys offer free case evaluations, so there is little downside to asking questions. This can help you determine your rights and whether joining a claim or lawsuit makes sense for your situation.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification report (PDF) from Delaware Attorney General

Related Data Breaches

View the full list of tracked data breaches →