ShinyHunters told BleepingComputer they accessed the Florida DMV “DAVID” database through a password-reset flaw that let them compromise multiple accounts in the system—accounts that allegedly belonged to DMV employees and an FBI agent. But last night, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) issued its own explanation, which does not quite match what the criminals claimed:
On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization. The data breach was quickly mitigated and no further breach has occurred or is ongoing.
The Department immediately launched an investigation, which determined that a criminal actor was able to take advantage of a single Plant City Police Department user’s credentials that were improperly housed on the employee’s personal electronic device.
In addition to providing the required notice of the security breach to the Office of the Attorney General pursuant to section 501.171, F.S., FLHSMV is partnering with the Florida Digital Service and the Florida Department of Law Enforcement in its response to the event.
As this Is an ongoing criminal investigation, further information will be released at an appropriate time in the future.
