INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters hackers breach Florida DMV database of DAVID employee
| 2026-09-08 16:35 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
On September 8, 2026, the ShinyHunters extortion gang claimed to have breached the Florida Department of Motor Vehicles (FLHSMV) database known as "DAVID", stealing over 200,000 records about drivers in the state. The attackers are believed to be behind this incident; however, no further information is available on their motivations or affiliations at this time. The breach affected approximately 200,000 individuals and involved unauthorized access to sensitive driver's license data. ShinyHunters added FLHSMV to its data leak site, warning users of the breach.
Technical Mitigations AI-generated
• Patch Microsoft September 2026 Patch Tuesday fixes, specifically addressing the two zero-days.
• Detect and hunt for indicators of DoppelCart fraud network activity using techniques such as IP blocking or machine learning-based anomaly detection.
• Block or hunt for ShinyHunters hackers' tactics, including exploiting vulnerabilities in Adobe Magento versions prior to patching.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
la•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
ad•••••.com
ww•••••.com
de•••••.com
ww•••••.com
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
Incident Timeline
2016 August
Threat actors exploited a vulnerability in Windows Server 2016 to trigger the 0xc0000409 error, which occurred during August updates.
Click on any entity below to view its context and source!
infrastructure
Windows
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
tactic
T1584.004 - Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
infrastructure
2016 Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
September 3rd
Threat actors claiming to be ShinyHunters hackers allegedly breached the Florida DMV's "DAVID" database starting on September 3rd.
Click on any entity below to view its context and source!
data_breach
200,000 records
This allegedly allowed them to steal over 200,000 data records since the breach began on September 3rd.
September 2026
Microsoft released a September 2026 Patch Tuesday update that addressed 966 vulnerabilities, including two zero-days, potentially impacting the security of various systems.
Click on any entity below to view its context and source!
organisation
Microsoft
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
966 flaws
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
2 days
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
2026/09/07
The FBI was contacted by BleepingComputer about a potential breach of the Florida DMV's "DAVID" database, which is being investigated.
Click on any entity below to view its context and source!
attribution
FBI
BleepingComputer contacted FLHSMV and the FBI yesterday about the incident and will update the story if we receive a response.
September 8, 2026
ShinyHunters hackers claimed a breach of Florida's "DAVID" DMV database through exploiting a password-reset flaw, allowing them to compromise multiple accounts and download associated records.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
[Image 34: ThreatLocker](
* Home
* News
* Security
* ShinyHunters hackers claim breach of Florida "DAVID" DMV database
# ShinyHunters hackers claim breach of Florida "DAVID" DMV database
By
###### Lawrence Abrams
* September 8, 2026
* 12:35 PM
* 1
!
## Who is ShinyHunters
ShinyHunters is an extortion gang known for targeting online web applications and cloud SaaS environments in data theft attacks.
Over the past year, threat actors using the ShinyHunters name have become one of the most prolific groups that conduct data theft and extortion attacks against companies worldwide.
"
Last night, ShinyHunters added FLHSMV to its data leak site, warning that it would leak the allegedly stolen data if the agency did not negotiate with them.
!
ShinyHunters told BleepingComputer they breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system.
When asked whether they are targeting additional DMVs, ShinyHunters told BleepingComputer they expect to announce other breaches over the coming weeks.
organisation
ThreatLocker
[Image 34: ThreatLocker](
* Home
* News
* Security
* ShinyHunters hackers claim breach of Florida "DAVID" DMV database
# ShinyHunters hackers claim breach of Florida "DAVID" DMV database
By
###### Lawrence Abrams
* September 8, 2026
* 12:35 PM
* 1
!
organisation
BleepingComputer
ShinyHunters told BleepingComputer they breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system.
organisation
Microsoft 365
After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
organisation
SSO
After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
organisation
Salesforce
After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
organisation
SAP
After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
organisation
Slack, Adobe
After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
infrastructure
Windows
Lawrence's area of expertise includes Windows, malware removal, and computer forensics.
organisation
the Florida Highway Safety and Motor Vehicles
DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver.
organisation
FLHSMV
DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver.
organisation
Social Security
This record includes the person's address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles.
organisation
HTML
Using this access, the threat actors say they iterated through the records by IDs and then downloaded the associated HTML and images for the drivers.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
the Winternals Defragmentation, Recovery
Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.
organisation
Administration Field Guide
Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.
organisation
Rootkits for Dummies
Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.
organisation
EU CRA
Check your EU CRA readiness in 5 questions.
2003 - 2026
ShinyHunters hackers claimed a breach of the Florida DMV database labeled "DAVID".
Click on any entity below to view its context and source!
organisation
Social & Feeds
* Advertising
* Write for BleepingComputer
* Social & Feeds
* Changelog
Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure
Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved
[]( "Back to Top")
2026/09/08
Threat actors using the ShinyHunters name breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Image 35: Florida
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
Novocure data breach affects more than 1,400 cancer patients
Ernst & Young data breach claimed by ShinyHunters extortion gang
Clop created custom web shell for Windchill data theft attacks
Data analyst sent to prison for stealing data, extorting employer
Wesco confirms security incident after ExfilSquad claims data theft
* Data Theft
* Department of Motor Vehicles
*
DMV
* Extortion
* Florida
* Password Reset
* ShinyHunters
*
Image 36: Florida DMV listed on the ShinyHunters data leak site
**Florida DMV listed on the ShinyHunters data leak site**
As proof of the breach, the threat actors released a screenshot of Jeffrey Epstein's record in the DAVID system.
More recently, the threat actors have been conducting voice phishing (vishing) attacks targetingOkta, Microsoft, and Google single sign-on (SSO) accounts, where they impersonate IT support staff to trick employees into entering credentials and multi-factor authentication (MFA) codes on phishing sites.
AsBleepingComputer first reported, the ShinyHunters group has also adopted device code vishing attacks to obtain Microsoft account authentication tokens.
ShinyHunters hackers claim breach of Florida "DAVID" DMV database.
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
The name ShinyHunters has long been associated withnumerousthreat actors who have conducteddata breaches since 2018.
Over the years, numerous arrests have been linked to the ShinyHunters name, including suspects connected to theSnowflake data-theft attacks,breaches at PowerSchool, and theoperation of the Breached v2 hacking forum.
However, even with these arrests, threat actors using the ShinyHunters name remain a threat to enterprises worldwide.
!
organisation
the Florida Department of Motor Vehicles
Image 35: Florida
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
data_breach
200,000 records
Image 35: Florida
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
organisation
Ernst & Young
Novocure data breach affects more than 1,400 cancer patients
Ernst & Young data breach claimed by ShinyHunters extortion gang
Clop created custom web shell for Windchill data theft attacks
Data analyst sent to prison for stealing data, extorting employer
Wesco confirms security incident after ExfilSquad claims data theft
* Data Theft
* Department of Motor Vehicles
*
organisation
Windchill
Novocure data breach affects more than 1,400 cancer patients
Ernst & Young data breach claimed by ShinyHunters extortion gang
Clop created custom web shell for Windchill data theft attacks
Data analyst sent to prison for stealing data, extorting employer
Wesco confirms security incident after ExfilSquad claims data theft
* Data Theft
* Department of Motor Vehicles
*
organisation
ExfilSquad
Novocure data breach affects more than 1,400 cancer patients
Ernst & Young data breach claimed by ShinyHunters extortion gang
Clop created custom web shell for Windchill data theft attacks
Data analyst sent to prison for stealing data, extorting employer
Wesco confirms security incident after ExfilSquad claims data theft
* Data Theft
* Department of Motor Vehicles
*
organisation
Data Theft
Novocure data breach affects more than 1,400 cancer patients
Ernst & Young data breach claimed by ShinyHunters extortion gang
Clop created custom web shell for Windchill data theft attacks
Data analyst sent to prison for stealing data, extorting employer
Wesco confirms security incident after ExfilSquad claims data theft
* Data Theft
* Department of Motor Vehicles
*
organisation
Department of Motor Vehicles
*
Novocure data breach affects more than 1,400 cancer patients
Ernst & Young data breach claimed by ShinyHunters extortion gang
Clop created custom web shell for Windchill data theft attacks
Data analyst sent to prison for stealing data, extorting employer
Wesco confirms security incident after ExfilSquad claims data theft
* Data Theft
* Department of Motor Vehicles
*
organisation
Google
More recently, the threat actors have been conducting voice phishing (vishing) attacks targetingOkta, Microsoft, and Google single sign-on (SSO) accounts, where they impersonate IT support staff to trick employees into entering credentials and multi-factor authentication (MFA) codes on phishing sites.
AsBleepingComputer first reported, the ShinyHunters group has also adopted device code vishing attacks to obtain Microsoft account authentication tokens.
organisation
MFA
More recently, the threat actors have been conducting voice phishing (vishing) attacks targetingOkta, Microsoft, and Google single sign-on (SSO) accounts, where they impersonate IT support staff to trick employees into entering credentials and multi-factor authentication (MFA) codes on phishing sites.
AsBleepingComputer first reported, the ShinyHunters group has also adopted device code vishing attacks to obtain Microsoft account authentication tokens.
organisation
DMV
ShinyHunters hackers claim breach of Florida "DAVID" DMV database.
organisation
theSnowflake
Over the years, numerous arrests have been linked to the ShinyHunters name, including suspects connected to theSnowflake data-theft attacks,breaches at PowerSchool, and theoperation of the Breached v2 hacking forum.
organisation
PowerSchool
Over the years, numerous arrests have been linked to the ShinyHunters name, including suspects connected to theSnowflake data-theft attacks,breaches at PowerSchool, and theoperation of the Breached v2 hacking forum.
infrastructure
Microsoft 365
[Image 42: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
BigBear Microsoft 365
[Image 42: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
victims
258 organizations
[Image 42: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
infrastructure
Windows
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
organisation
Stack Protection
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
organisation
Windows Registry
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
organisation
the Windows Registry
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
infrastructure
Linux
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
organisation
APM
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
organisation
Hackers
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
organisation
Magento
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
organisation
Adobe
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
organisation
DoppelCart
[Image 7: DoppelCart fraud network uses 119,000 fake shops to steal credit cards DoppelCart fraud network uses 119,000 fake shops to steal credit cards](
* !
organisation
IP
[Image 31: How to change IP address.jpg) How to change IP address](
* !
organisation
safely.jpg
Access the dark web safely.jpg)
organisation
PornHub
Initiallyfocusing on Salesforce and other cloud SaaS environments, the threat actors are linked to a growing number of breaches involving companies such asGoogle,Cisco,PornHub, andonline dating giant Match Group.
organisation
Match Group
Initiallyfocusing on Salesforce and other cloud SaaS environments, the threat actors are linked to a growing number of breaches involving companies such asGoogle,Cisco,PornHub, andonline dating giant Match Group.
organisation
CTI
[Image 44: CTI Starter Kit + 2026 SANS CTI Survey CTI Starter Kit + 2026 SANS CTI Survey](
* !
organisation
Upcoming Webinar
[Image 39: ThreatLocker](
Upcoming Webinar
!
organisation
ClickFix
Blockchain Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain](
S ponsor Posts
* !
organisation
Freestar.com
Submitting...
SUBMIT
Freestar.com
!
financial
3 hours
Image 38: johnlsenchak Photo
###### johnlsenchak - 3 hours ago
*
Tactical Metrics
Metrics
data_breach
200,000
Records
Click for context!
Image 35: Florida
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
This allegedly allowed them to steal over 200,000 data records since the breach began on September 3rd.
Metrics
infrastructure
Microsoft 365
Affected Product
[Image 42: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox.
Metrics
victims
258
Organizations
[Image 42: Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
infrastructure
Windows
Affected Product
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
Lawrence's area of expertise includes Windows, malware removal, and computer forensics.
Metrics
infrastructure
2,016
Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
Metrics
infrastructure
Linux
Affected Product
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
Metrics
financial
3
Hours
Image 38: johnlsenchak Photo
###### johnlsenchak - 3 hours ago
*
Intelligence Sources
BleepingComputer
2026-09-08
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:29
Comprehensive Tactical Telemetry
Highly Correlated Entities
46x
organisation
Identified Entity
the Florida Department of Motor Vehicles
entity
7x
tactic
Cyber Operation Type
Extortion
tactic
7x
timeline
Temporal Reference
September 8, 2026
date
5x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
3x
infrastructure
Affected Product
Microsoft 365
software
2x
general metric
Windows
11
windows
Contextual Telemetry
Context Block
17 METRICS
target region
Target Country
United States
country
threat actor
APT Group
ShinyHunters
actor
data breach
Records
200,000
records
general metric
Cancer Patients
1,400
cancer patients
general metric
Microsoft
365
microsoft
victims
Organizations
258
organizations
infrastructure
Windows Server
2,016
windows server
attribution
Attributing Entity
FBI
authority
general metric
Flaws
966
flaws
general metric
Days
2
days
general metric
Fake Shops
119,000
fake shops
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Hacked Sites
5,400
hacked sites
general metric
Questions
5
questions
general metric
%
37
%
financial
Hours
3
hours
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.