One cop's phone, one saved password, and Florida's driver database was open
Florida says its driver records were reached with a single police employee's login, stored where it shouldn't have been. The hackers tell a different story about how they got in.
If you have a Florida driver's license, your record sits in a state system called DAVID. On September 4, 2026, the Florida Department of Highway Safety and Motor Vehicles learned someone had been inside it. The agency says the intruder used working credentials belonging to one user at the Plant City Police Department — credentials that had been improperly stored on that employee's personal device.
The extortion group ShinyHunters claimed it took more than 200,000 driver records. Florida has not confirmed that number, and has not said how many records were accessed or stolen. As proof, the hackers published a screenshot of a DAVID record belonging to Jeffrey Epstein, showing personal and vehicle information.
A driver database is not a bank account. You cannot change your date of birth, your address history, your license photo or your vehicle after a leak. That is what makes this category of breach different from a stolen card number: there is no reissue. Whoever holds a copy holds it permanently, and the people in it were never customers who agreed to anything — they just needed to drive.
The access point matters more than the database. Florida's account is that one person's saved password on a personal phone or laptop was enough to reach records of strangers. Police departments across the country hold that same kind of access to state driver systems. The weakest link is not the state server — it is every device belonging to every person who has ever been granted a login.
One saved password. Hundreds of thousands of strangers' records.
And then there is the part that does not line up. Florida says the attacker used stolen credentials from one police user. ShinyHunters says it exploited a password reset flaw to get into multiple DAVID accounts, including ones belonging to DMV employees and an FBI agent, then walked through record IDs one by one, downloading pages and images starting September 3. Those are two different stories. One says a careless employee. The other says the system itself let people in. We do not know which is right — and until someone shows the evidence, neither does anyone reading about it.
Anyone with a Florida license — including students and people in their twenties who got one at 16 and have never thought about it since, and who now have an address history and a license photo sitting in someone else's archive with no way to change it. Also anyone whose job comes with a login to a government system: the lesson here is not about hackers, it's about where you let your browser save passwords on your own phone. And everyone in the wider group whose personal data lives in a state database they never chose to join — you don't opt into a DMV.
FLHSMV says it notified the Florida Office of the Attorney General and is working with the Florida Digital Service and the Florida Department of Law Enforcement. It also says this is an ongoing criminal investigation and that "further information will be released at an appropriate time in the future" — no date given. The two numbers to watch: whether the state ever confirms a record count, and whether it addresses the password reset flaw ShinyHunters described. ShinyHunters told BleepingComputer it had lost access and believed the flaw was being patched.
The proof the hackers chose to publish was Jeffrey Epstein's record. A famous name gets attention — but the record next to it in that database belongs to someone who will never be named in any article. That person's file is just as copied, and nobody will tell them individually.
Sources: Bleeping Computer, September 11, 2026 — "Florida confirms DMV database breached via stolen police account" by Lawrence Abrams; FLHSMV statement posted to X.
Государственная база водительских прав штата оказалась открыта через один украденный полицейский логин — и официальная версия властей расходится с тем, что рассказывают сами взломщики.
Written by THE TELL’s AI newsroom. how we work · corrections