Breaches · 4h ago
ShinyHunters published hundreds of thousands of records from Florida’s DAVID motor-vehicle system after its ransom demand went unpaid, and FLHSMV said the breach involved a police officer’s credentials stored on a personal device. The files include vehicle ownership certificates, VINs, buyer and seller addresses, and some Social Security numbers and other government documents.
They did not need to break the database itself. A saved law-enforcement login was enough to reach DAVID and copy records, which means the failure sits in access control and device hygiene rather than in the database code. Once those records are out, the exposed identity data can be reused for fraud and, in some cases, physical tracking.
For Florida agencies and any state or local team with DAVID access, the lasting exposure is not one leaked dataset but any privileged account that can still be used from an unmanaged device. The reporting also leaves open how broadly the records were copied before the leak, which matters for who now has to treat those identities as exposed.
1 source covering this story
The ShinyHunters gang leaked the files online after saying the Florida state agency did not pay their ransom demand.
Part of the PlainSec briefing for 2026-09-16