Florida Confirms DAVID Driver Database Breach After Hackers Claim 200,000 Records

The Florida Department of Highway Safety and Motor Vehicles has confirmed that its DAVID driver database was breached earlier this month, after an international extortion group claimed it had stolen more than 200,000 driver records and threatened to publish them. The agency says its investigation traced the intrusion to compromised credentials belonging to a single Plant City Police Department user, credentials that had been improperly stored on that employee's personal device.
DAVID, short for Driver and Vehicle Information Database, is the system Florida law enforcement officers use to look up driver license records during traffic stops, investigations and routine field work. It contains the kind of information that is difficult or impossible for an individual to change: name, date of birth, address, license number, signature image and driver license photograph. That makes a breach of DAVID meaningfully different from a stolen credit card number.
The department learned of the breach on September 4 and says the intrusion was mitigated quickly, with no further unauthorized access continuing. The group claiming responsibility, which operates under the name ShinyHunters, added the agency to its data leak site on September 7 and set a deadline for the state to respond. What Floridians still do not have is a clear public accounting of exactly whose records were accessed.
What the state has confirmed
According to the agency's account, the attacker did not exploit a flaw in DAVID itself. Instead, the intruder used valid login credentials that belonged to a law enforcement user and had been stored where they should not have been. Once inside, the attacker had the access rights of that account, which in DAVID's case means the ability to query driver records.
The agency has described the incident as an ongoing criminal investigation and has said the breach was contained. It has not, as of this writing, published a detailed notification describing the number of Floridians affected or the specific categories of data accessed. Florida law requires notification to affected individuals when personal information is compromised, subject to timing allowances when law enforcement determines that notice would interfere with an investigation.
The attackers tell a different story about how they got in. ShinyHunters has claimed it exploited a password reset weakness to gain access to multiple DAVID accounts, including accounts belonging to department employees and, in the group's telling, a federal agent. The group says it then iterated through record identifiers and downloaded the associated pages and images beginning on September 3.
Those two accounts are not fully reconcilable. A single stolen credential and a password reset flaw affecting multiple accounts describe different failure modes with different implications for how many records were reachable. Extortion groups routinely overstate the scope of what they hold in order to increase pressure, and state agencies under investigation routinely describe the narrowest confirmed scope. The truth may only become clear through the formal breach notification.
Why DAVID matters more than an ordinary breach
Most large data breaches involve information that can be rotated. A stolen password can be changed. A compromised credit card can be reissued. The data in a driver license record cannot be reissued in any practical sense.
A driver license number, full legal name, date of birth, home address and a signature image together constitute most of what is needed to open accounts, apply for credit, or construct a convincing identity document. The license photograph adds a biometric element. For Floridians whose records were taken, the exposure is effectively permanent.
There is a second category of risk that is specific to certain Floridians. DAVID contains records for people whose home addresses are legally protected, including law enforcement officers, judges, prosecutors and participants in address confidentiality programs for survivors of domestic violence and stalking. Florida statute provides for exempting those addresses from public records, but the exemption protects against public records requests, not against someone who has obtained access to the underlying database.
DAVID has also had a history of misuse from the inside. Florida agencies have disciplined and in some cases prosecuted officers for looking up records they had no legitimate reason to access. The system logs queries, which is how those cases are typically detected, and the same logging is presumably what allowed the state to identify which account was used in this intrusion.
How the credential was lost
The department's account points to a specific and preventable failure: a law enforcement user stored DAVID credentials on a personal electronic device. That is a policy violation in virtually every agency that uses the system, and it is also an extremely common one.
Officers who work across multiple systems face a real usability problem. Law enforcement personnel typically hold credentials for state driver records, criminal history systems, records management systems, computer-aided dispatch and agency email, each with its own password requirements and rotation schedules. When those systems do not support single sign-on or hardware-based authentication, users find workarounds.
The broader lesson is about architecture rather than individual conduct. A system holding the driver records of more than 17 million licensed Floridians that can be fully queried by anyone possessing one username and password is, by design, dependent on the security hygiene of thousands of individual officers across hundreds of agencies. Phishing-resistant multifactor authentication, hardware tokens and query rate limiting are the standard mitigations, and the incident raises the question of how completely they were deployed.
What Floridians should do
Until the state publishes a notification identifying affected individuals, Floridians cannot know whether their record was among those taken. That uncertainty argues for defensive steps that are useful regardless.
- Place a security freeze with all three major credit bureaus. A freeze is free under federal law, prevents new credit accounts from being opened in your name, and can be lifted temporarily when you need it.
- Be skeptical of unsolicited contact that references your driver license details. Criminals holding accurate personal data use it to make fraudulent calls, texts and emails more convincing.
- Watch for mail from creditors or government agencies about accounts you did not open, which is often the first sign of identity misuse.
- If you participate in an address confidentiality program or have a protected address, contact the program administrator for guidance on your specific situation.
Floridians should also be alert to a predictable secondary wave: fraudulent breach notification messages. After any publicized breach, criminals send messages impersonating the affected agency and directing recipients to fake credit monitoring sign-up pages. Official notification from a Florida state agency will not arrive as an unsolicited text message with a link.
Who ShinyHunters are
The group claiming responsibility is not new. ShinyHunters has been linked to a long series of large-scale data thefts against corporate and government targets over several years, operating on a consistent model: obtain access, exfiltrate data in volume, then publicize the theft and demand payment to prevent publication.
The model differs from ransomware in an important way. Ransomware encrypts a victim's systems and demands payment to restore access, which means a victim with good backups can refuse. Pure data extortion offers no such option. Once the data is copied, the victim cannot un-copy it, and paying provides only a promise that the attackers will not publish.
Government agencies are generally poor extortion targets for exactly that reason. Public entities rarely pay, both because policy discourages it and because the decision would become a public record. The practical consequence is that data stolen from government systems is more likely to end up published than data stolen from a private company.
The group added the department to its leak site on September 7 and set a publication deadline. Whether that deadline passed without publication, or whether the data has since appeared, is the detail that determines the real-world exposure for affected Floridians.
What Florida law requires
Florida's Information Protection Act governs how entities, including government agencies, must respond to a breach of personal information. It requires notice to affected individuals, generally within 30 days of determining that a breach occurred, and notice to the Department of Legal Affairs when the breach affects 500 or more Floridians.
The statute allows a delay in notification when a law enforcement agency determines that notice would interfere with a criminal investigation, and the department has described this matter as an ongoing criminal investigation. That provision is a recognized and legitimate exception, but it is not unlimited, and the obligation resumes once the investigating agency lifts the hold.
Driver license numbers are explicitly within the statutory definition of personal information in Florida, as are dates of birth in combination with a name. A breach reaching those fields falls squarely inside the notification requirement.
The department's public acknowledgment of an ongoing investigation is not itself the notification the statute contemplates. Individual notice must describe what happened, what information was involved and what the affected person can do, which is information Floridians do not yet have.
The accountability questions
Several questions remain open. The first is scope. The state has not said how many records were accessed, and the gap between the agency's description and the attackers' claim of 200,000 records is large enough to matter.
The second is notification timing. The breach was discovered on September 4. Florida's information protection statute sets expectations for notifying affected individuals, and the clock on that obligation is a matter of public interest, particularly for a database whose contents cannot be changed after exposure.
The third is systemic. DAVID is accessed by hundreds of agencies and thousands of users. If one improperly stored credential could produce this outcome, the same exposure exists at every other agency with DAVID access. Whether the state responds with stronger authentication requirements, tighter query monitoring or audit obligations on participating agencies will determine whether this incident is an isolated failure or a preview.
What's next
The criminal investigation is ongoing, and the department has not said which agencies are involved. Breaches of state systems by international groups typically draw federal law enforcement participation, though the state has not confirmed the composition of the investigative team.
ShinyHunters has a pattern of publishing data when extortion demands are not met, which means the practical question for affected Floridians is whether the records appear publicly. If they do, the downstream identity theft risk becomes concrete rather than theoretical.
The Legislature returns to Tallahassee for the 2027 session in the new year, and state data security has a way of reaching the agenda after an incident like this one. Whether that produces funding for authentication upgrades, statutory changes to breach notification timelines, or simply committee hearings will be worth watching. For now, Floridians are left waiting on a notification that has not yet arrived.
Spotted an issue with this article?
Have something to say about this story?
Write a letter to the editor

