INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters hackers breach Florida DMV database of DAVID employee

| 2026-09-08 16:35 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
On September 8, 2026, the ShinyHunters extortion gang claimed to have breached the Florida Department of Motor Vehicles (FLHSMV) database known as "DAVID", stealing over 200,000 records about drivers in the state. The attackers are believed to be behind this incident; however, no further information is available on their motivations or affiliations at this time. The breach affected approximately 200,000 individuals and involved unauthorized access to sensitive driver's license data. ShinyHunters added FLHSMV to its data leak site, warning users of the breach.
Technical Mitigations AI-generated
• Patch Microsoft September 2026 Patch Tuesday fixes, specifically addressing the two zero-days. • Detect and hunt for indicators of DoppelCart fraud network activity using techniques such as IP blocking or machine learning-based anomaly detection. • Block or hunt for ShinyHunters hackers' tactics, including exploiting vulnerabilities in Adobe Magento versions prior to patching.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

la•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
ad•••••.com
ww•••••.com
de•••••.com
ww•••••.com
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA educationeducation
Incident Timeline
‎2016 August
Threat actors exploited a vulnerability in Windows Server 2016 to trigger the 0xc0000409 error, which occurred during August updates.
infrastructure Windows
tactic T1584.004 - Server
infrastructure 2016 Windows Server
‎September 3rd
Threat actors claiming to be ShinyHunters hackers allegedly breached the Florida DMV's "DAVID" database starting on September 3rd.
data_breach 200,000 records
‎September 2026
Microsoft released a September 2026 Patch Tuesday update that addressed 966 vulnerabilities, including two zero-days, potentially impacting the security of various systems.
organisation Microsoft
general_metric 966 flaws
general_metric 2 days
‎2026/09/07
The FBI was contacted by BleepingComputer about a potential breach of the Florida DMV's "DAVID" database, which is being investigated.
attribution FBI
‎September 8, 2026
ShinyHunters hackers claimed a breach of Florida's "DAVID" DMV database through exploiting a password-reset flaw, allowing them to compromise multiple accounts and download associated records.
threat_actor ShinyHunters
organisation ThreatLocker
organisation BleepingComputer
organisation Microsoft 365
organisation SSO
organisation Salesforce
organisation SAP
organisation Slack, Adobe
infrastructure Windows
organisation the Florida Highway Safety and Motor Vehicles
organisation FLHSMV
organisation Social Security
organisation HTML
organisation The Blue Report 2026
organisation the Winternals Defragmentation, Recovery
organisation Administration Field Guide
organisation Rootkits for Dummies
organisation EU CRA
‎2003 - 2026
ShinyHunters hackers claimed a breach of the Florida DMV database labeled "DAVID".
organisation Social & Feeds
‎2026/09/08
Threat actors using the ShinyHunters name breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
threat_actor ShinyHunters
organisation the Florida Department of Motor Vehicles
data_breach 200,000 records
organisation Ernst & Young
organisation Windchill
organisation ExfilSquad
organisation Data Theft
organisation Department of Motor Vehicles *
organisation Google
organisation MFA
organisation DMV
organisation theSnowflake
organisation PowerSchool
infrastructure Microsoft 365
organisation BigBear Microsoft 365
victims 258 organizations
infrastructure Windows
organisation Stack Protection
organisation Windows Registry
organisation the Windows Registry
infrastructure Linux
organisation APM
organisation Hackers
organisation Magento
organisation Adobe
organisation DoppelCart
organisation IP
organisation safely.jpg
organisation PornHub
organisation Match Group
organisation CTI
organisation Upcoming Webinar
organisation ClickFix
organisation Freestar.com
financial 3 hours
Tactical Metrics
Metrics
data_breach
200,000
Records
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
victims
258
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
2,016
Windows Server
Metrics
infrastructure
‎Linux
Affected Product
Metrics
financial
3
Hours
Intelligence Sources
BleepingComputer 2026-09-08