Skip to content
  • Home
  • Services
    • Web Design & Marketing
      Digital Marketing
      Cybersecurity & Pen Testing
      Cloud Backup & Disaster Recovery
      Managed IT & Infrastructure
      Cloud & Hosting Solutions
      IT Support & Troubleshooting
      Email Solutions
      Cybersecurity Training
  • About
  • Blog
  • Contact
  • Partner Portal
    • Support Portal
    • Partner Dashboard
Request A Consultation

Cybersecurity

/

September 9, 2026

Florida’s Driver Database and the ShinyHunters Claim: What’s Confirmed, What Isn’t, and What to Do

If you have a Florida driver’s license — or family who does — you’ve probably seen the headlines: a hacking group says it broke into the state’s driver database and stole more than 200,000 records, and it’s threatening to publish them on September 11 unless the state pays up. As proof, the group posted what it says is the full driver record of a notorious, deceased public figure — Social Security number and all. It’s the third major identity-document story in barely a week, and it’s spreading fast.

Here’s what we’re going to do with it. First, separate what’s actually confirmed from what’s merely claimed, because on this story the gap between the two is wide and it matters. Second, explain what the system in question really is — it’s not the website you renew your tags on, and that distinction changes how you should think about it. Third, give Floridians and everyone else a short, practical list of what to do. And fourth, pull out the two lessons that apply to every business, because the way the attackers say they got in has nothing to do with driver’s licenses and everything to do with a door your business almost certainly has.

Claimed versus confirmed

Extortion groups have every incentive to make an intrusion sound as large and as certain as possible — that’s how they get paid. So here is the honest ledger as of this writing:

What the group claimsWhat’s actually confirmed
It breached DAVID, Florida’s Driver and Vehicle Information Database, beginning around September 3The group posted a listing titled “State of Florida DMV” on its leak site on September 7 — independently logged by a breach-tracking service. The listing exists; the breach behind it is unverified.
It stole more than 200,000 driver records before losing accessNo confirmation of any number. The state agency and the FBI had not responded to reporters’ inquiries as of publication.
It got in through a password-reset flaw and took over multiple accounts, including DMV employees’ and an FBI agent’sEntirely self-reported. An independent outlet said it could not verify the claims, the authenticity of the sample record, or whether the data came from a direct compromise of the agency.
The flaw is being patched and the group has since lost accessUnverified — and it’s the group’s own account, not the state’s.
It will publish the data on September 11 unless the state makes contactThe deadline is real in the sense that it’s posted. Whether the data exists, and whether it will be released, remains to be seen.

Two things are worth adding for context. The group told reporters the state has not engaged with it, which is consistent with law-enforcement guidance not to negotiate with extortionists. And the sample record it posted, if genuine, is alarming in its detail: it reportedly shows an address, Social Security number, date of birth, license number, issuance and expiration dates, and registered vehicles, with tabs for license transactions, insurance, prior vehicles, and parking permits. That’s not a name and an email. That’s a complete identity file.

What DAVID actually is — and why it matters

Here’s a point most of the coverage skips past, and it reframes the whole story. DAVID is not the public DMV website. You’ve never logged into it. It is a restricted, internal lookup system that Florida’s Department of Highway Safety and Motor Vehicles makes available to law enforcement, criminal-justice officials, and other authorized users so they can pull up driver and vehicle records — the tool a police officer uses to check your license during a traffic stop, the system the state describes as indispensable for law enforcement.

That cuts two ways. On one hand, it means this wasn’t some consumer web form that got scraped; if the claim holds, the attackers got inside a system built only for verified government users — which is exactly why the FBI-agent detail, if true, is so striking. On the other hand, it means the records at stake aren’t limited to people who “used” some service. DAVID holds the driver and vehicle records of Florida’s drivers, period. Nobody opted in. The 200,000 figure, if accurate, is simply how many the group managed to pull before it lost access — not a description of some particular group of people who did something. Any Florida driver could be among them.

One more note: this appears to be a separate incident from the enormous driver’s-license-scan story we covered last week involving an identity-verification vendor. Different attackers, different system, different data. But arriving in the same week, alongside a breach of millions of airport customers’ details, they add up to an unmistakable pattern: identity documents have become one of the most valuable things criminals steal, precisely because — unlike a password — the details on them can’t be changed.

If you’re a Florida driver (or love one)

Because nothing is confirmed, there’s no official notification and no mandated action yet. But the sensible posture is the same one we recommended last week, and it costs little to adopt now rather than after a confirmation that may or may not come:

  1. Freeze your credit if you haven’t already. If Social Security numbers and dates of birth really were taken, the primary danger is someone opening accounts in your name. A freeze at all three bureaus (Equifax, Experian, TransUnion) blocks that, is free, doesn’t affect your score, and can be lifted whenever you need. If you did this after last week’s story, you’re already covered.
  2. Expect DMV-impersonation scams, and refuse them. This is the specific new risk. A scammer holding a driver record can quote your license issuance date or your registered vehicle back to you, which makes a fake “FLHSMV compliance” call, a “your registration has a problem” text, or a “confirm your details to avoid suspension” email suddenly sound legitimate. Rule: the DMV doesn’t call, text, or email you demanding payment or personal details through a link. If you get one, hang up or delete it, and contact the agency yourself through its official website.
  3. Watch for new-account and vehicle-related fraud. Keep an eye on credit reports and accounts. A complete driver record is enough for many identity-theft schemes, and vehicle details can be used for title, registration, or insurance fraud.
  4. Be doubly wary of “check if you’re affected” messages. There is no lookup tool for this. Anything offering to tell you whether your record was in the breach is a scam riding the headlines.
  5. Turn on two-factor authentication for your email and financial accounts, so identity details alone aren’t enough to get in.

Not in Florida? Don’t tune out. A source told reporters the same group is targeting other states’ motor-vehicle systems, using social engineering, and the group itself said it expects to announce more such breaches in the coming weeks. Every state runs a system like DAVID. The precautions above are cheap insurance for anyone, anywhere, and the credit freeze in particular is worth doing once and being done with it.

Business lesson one: the password reset is a side door

Now to the part that has nothing to do with driver’s licenses and everything to do with your business. Notice what the attackers didn’t claim. They didn’t claim to have cracked the database, defeated its encryption, or exploited some exotic flaw in the data itself. They claim they abused the password-reset process to take over legitimate accounts — and then simply used those accounts to look up records one after another, exactly as an authorized user would. If that’s true, the database’s security did its job. The login was the failure.

A password-reset flow is supposed to be the most locked-down part of any login system, because it’s the one path that, by design, lets someone in without knowing the password. If it’s built carelessly — a reset link that can be guessed or intercepted, a reset that only asks for information an attacker could find, a helpdesk that resets a password for anyone who calls with a convincing story — it becomes a side door that bypasses everything else. Security people have flagged this class of weakness for years in government portals and business systems alike, and it keeps working because everyone focuses on the front door.

Ask this about every system your business runs with a login: how does someone reset a forgotten password? If the answer is “click a link in an email” — is that link protected, does it expire quickly, and does the reset require a second verification step? If the answer is “call the office and we’ll reset it” — how does whoever answers verify it’s really the employee? An attacker who can trigger a reset owns the account, and owns everything that account can see. The most secure vault in the world is only as strong as the process for handing out replacement keys.

Business lesson two: the deadline is the attack

Look at the shape of the extortion itself. The group listed the state on September 7 and set a deadline of September 11 — four days. Confirming an intrusion, figuring out what was actually taken, and deciding how to respond honestly takes far longer than four days; that’s what forensic investigation is. The deadline isn’t calibrated to the investigation. It’s calibrated to panic. The gap between what an honest investigation requires and what the attacker allows is exactly what they’re trading on: they want a decision made under pressure, before the facts are in.

Every business that’s ever extorted faces the same clock, and the answer is the one we gave in our recent post about Berlin refusing its ransom: the power to not panic is earned in advance. If you already know what data you hold, already have backups an attacker can’t reach, already have a plan for who you’d notify and how, and already have someone to call who knows your environment, then a four-day deadline is an annoyance rather than a crisis. If you have none of those things, the deadline works exactly as designed. Prepare on a calm day, and the countdown loses its power.

Worth asking about your own business: For each system your team logs into — email, accounting, your website, customer portals — how are passwords reset, and could a stranger with a good story trigger one? * Does every account with access to sensitive data require a second verification step, especially for resets? * If an extortionist posted your business name with a four-day deadline tomorrow, would you know what they might actually have — or would you be guessing under pressure? * And do you have someone to call in the first hour?

The takeaway

Until Florida’s motor-vehicle agency or the FBI speaks, this remains a claim — a serious, plausible, well-documented claim, but a claim from people who profit from being believed. The right response is neither to dismiss it nor to panic, but to take the cheap, sensible precautions that are worth doing regardless, and to watch for the DMV-impersonation scams that will follow whether or not the underlying breach is real. If the data is released on the 11th, or the state confirms, the advice above doesn’t change; it just becomes urgent.

For businesses, the story is a reminder that the most valuable database in the state was allegedly opened not by breaking the lock but by abusing the process for replacing lost keys — and that a criminal’s deadline is a weapon aimed at your composure. Both of those are things you can fix before anyone tests them. Our environment review looks at every login your business depends on, including how passwords get reset and whether a convincing stranger could talk their way into an account, and helps you build the preparation that turns an extortion countdown into something you can calmly wait out. The attackers in this story went looking for a side door. Let’s make sure yours is locked.

Schedule Your Small Business Environment Review
Is Your Business a Soft Target?
Take our Free Cyber Instinct Quiz

Sources: BleepingComputer (original reporting, September 8, 2026, including the group’s statements to the outlet); CyberInsider; Cyber Magazine; Ransomware.live (leak-site listing logged September 7); additional analysis from Tech-Insider and others, September 2026. As of publication, the Florida Department of Highway Safety and Motor Vehicles and the FBI had not confirmed a breach or responded to press inquiries; every detail of the intrusion, its scope, and its method is the group’s own claim and is presented here as such. This incident appears unrelated to the separate identity-verification-vendor exposure reported the previous week.

From the same category

Florida’s Driver Database and the ShinyHunters Claim: What’s Confirmed, What Isn’t, and What to Do

Cybersecurity

/

September 9, 2026

Why Hackers Hit a ‘Tiny’ Power Plant and Small Water Systems — and What It Means for Small Business

Cybersecurity

/

August 27, 2026

China Targeted NASA and the Federal Reserve — Using Hijacked Devices Like Yours

Cybersecurity

/

August 27, 2026

Your Website Should Go to School Every Day: A Back-to-School Report Card for Small Business

Web Design

/

August 23, 2026

One Click, One Mailbox: How a Missile-Defense Supplier Got Breached (And Why ‘We’re Too Small’ Is a Myth)

Cybersecurity

/

August 20, 2026

How Hackers Reached a Power Plant Through a Wind Farm: The Trusted-Connection Risk in Your Business

Cybersecurity

/

August 20, 2026

The Ransomware That Hunts Your Backups: What Gunra Teaches About Real Recovery

Cybersecurity

/

August 20, 2026

The Fake Job Offer That Installs Malware: Why Even Technical Experts Fall for It

Cybersecurity

/

August 20, 2026

One Attendee Could Take Over the Whole Meeting: The Zoom Flaw and Why ‘Update Now’ Matters More Than Ever

Cybersecurity

/

August 20, 2026

America Just Cracked Its Ban on Private Hacking: What the New Hack-Back Memo Really Means

Cybersecurity

/

August 20, 2026

Attackers Could Command Spacecraft Through NASA Software — And the Mistakes Were Utterly Ordinary

Cybersecurity

/

August 20, 2026

The Catalogue: Every Confirmed US and Allied Offensive Cyber Operation We Can Point To

Cybersecurity

/

August 8, 2026

IT solutions for the small business

Web design, cybersecurity, cloud backup, managed IT +
Backed by 20+ years of enterprise experience.

Sales@PendergrassConsulting.com
+1 252 432 3325
Request A Consultation
Navigate
  • Home
  • About
  • Contact
  • Support Portal
  • Partner Dashboard
  • Blog
Services
  • Web Design
  • Digital Marketing
  • Email
  • IT Support & Troubleshooting
  • Managed IT & Infrastructure
  • Cloud Backup & Disaster Recovery
  • Cloud & Hosting Solutions
  • Cybersecurity & Pen Testing
  • Cybersecurity Training
Connect
Facebook
X

© 2026

All Rights Reserved

Pendergrass Consulting

Go to Top

Book your consultation!

Have questions?  Ideas?  Don’t know where to start?
Fill out the form below & our specialist will contact you.

  • Home
  • Services
    • Web Design & Marketing
    • Digital Marketing
    • Email Solutions
    • Cloud Backup & Disaster Recovery
    • IT Support & Troubleshooting
    • Managed IT & Infrastructure
    • Cloud & Hosting Solutions
    • Cybersecurity & Pen Testing
    • Cybersecurity Training
  • About
  • Blog
  • Contact
  • Partner Portal
    • Support Portal
    • Partner Dashboard
Book a consultation