Florida DAVID Database: 200,000 Driver Records Claimed by ShinyHunters via a Police Account
> TL;DR: Florida's Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed that an international cybercrime organization accessed the DAVID driver database, with the breach discovered September 4, 2026. The ShinyHunters extortion gang claims more than 200,000 driver records stolen. Per the agency, the attacker used compromised credentials belonging to a Plant City Police Department user, "improperly stored on the employee's personal electronic device." ShinyHunters tells a different story: a password reset flaw, access to multiple accounts (DMV employees, an FBI agent), and enumeration of record IDs starting September 3.
Two diverging versions — and why it matters
The official version (one account, credentials stored on a personal device) and the attackers' version (a reset flaw, multiple accounts, mass enumeration) are not cosmetic differences: they demand different remediations. A stolen credential on a personal phone is fixed with BYOD rules and MFA. A password-reset flaw allowing takeover of arbitrary accounts — including an FBI agent's — is a product defect that potentially affects every user of the system.
ShinyHunters' published evidence leans toward an extensive compromise: the group shared a DAVID record for Jeffrey Epstein (personal and vehicle information) and described systematic harvesting by iterating over record IDs. The agency has confirmed neither volume nor method, deferring to an ongoing criminal investigation — the Florida Attorney General, Florida Digital Service, and Florida Department of Law Enforcement are all involved.
Why this matters to you
DAVID is exactly the kind of system found in every B2B SaaS: a high-privilege back office where institutional accounts (customers, partners, authorities, support) access individual records — in your case, employee files, payslips, health data, or identities. The three failures in this incident are the three back-office classics:
What to do
The broader lesson
The same ShinyHunters gang appears across this season's cases (Brevo/Trezor via ShipMonk, the Odido claim, and now Florida). Extortion groups are industrializing: one access, one database, one ransom demand, one public leak on refusal. The question is no longer "are our passwords strong" but "how many records can one compromised account extract overnight, and what stops it."
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Revolut: Passports, KYC Selfies, and Bitcoin History Handed to an Attacker Impersonating a Government Agency
Revolut (80+ million customers) has notified a data breach: an attacker requested personal data by email from a government agency's domain, with valid domain authentication credentials. Copies of passports, facial verification selfies, IBAN statements, and complete transaction history (including Bitcoin) were disclosed. Suspected targeting of high-net-worth users per ZachXBT.
Brevo Hacked: Trezor Phishing Sent from help@trezor.io, 347,000 Emails Targeted
On September 9, 2026, an unauthorized actor accessed French email platform Brevo (formerly Sendinblue), compromising 120 customer accounts including Trezor's. Fake security alerts went out from the genuine help@trezor.io address to 347,000 subscribers; 2,500 people clicked the malicious link before the domain was taken down in 20 minutes.
Zoom CVE-2026-53412: a critical account takeover in the Windows desktop client
An improper input validation flaw (CVSS 9.8) in Zoom Workplace for Windows, the VDI Client, and the Meeting SDK lets an unauthenticated attacker take over accounts via network access. Affects versions before 7.0.0. Fix available.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.