# ShinyHunters Claims Florida DMV's DAVID Database — 200,000 Driver Records on the Block


Florida's Department of Motor Vehicles runs a system called DAVID — Driver And Vehicle Information Database — that most residents have never heard of and nearly every law enforcement agency in the state uses daily. It holds exactly what a threat actor would want: full legal names, addresses, dates of birth, license numbers, and vehicle registration data tied together in a clean, queryable format. This week, ShinyHunters said they have it.


The extortion gang posted a claim that they breached the online platform tied to DAVID and walked out with more than 200,000 records on Florida drivers. No ransom demand has been publicly published yet. No statement from the Florida DHSMV has been issued confirming or denying the breach as of this writing.


## What DAVID Actually Is


Most breach coverage glosses over the system that got hit. DAVID isn't just a DMV backend — it's the statewide clearinghouse that law enforcement, insurance investigators, repossession agents, and licensed private investigators query to pull vehicle and driver data. Florida Statute 119.0712 governs access. Authorized users pull records that include physical descriptions, address history, and the full suite of identity anchors that make DMV data so persistently valuable to fraud rings.


The 200,000 figure is worth scrutinizing. Florida has roughly 15 million licensed drivers. If this number is accurate, it could represent a targeted query rather than a mass exfiltration — meaning the attacker may have run searches against specific cohorts, zip codes, or demographic slices rather than dumping the whole table. That's actually a more sophisticated operation than a brute bulk pull, and it raises questions about what access vector was used and whether credentials belonging to an authorized DAVID user were involved.


## ShinyHunters' Pattern


ShinyHunters has been one of the most active extortion actors of the past several years. Their portfolio includes Ticketmaster (560 million records in 2024 via the Snowflake credential-stuffing campaign), AT&T (tens of millions of call records), and dozens of mid-tier SaaS breaches that don't make the front page. The group's track record of releasing partial samples to validate claims before demanding payment is consistent — so the absence of a data sample in this claim is notable. Either the listing is very fresh, the sample is pending, or this is an unverified claim riding on the group's reputation.


What's changed about ShinyHunters since 2024 is that at least one member, Sebastien Raoult, was convicted in the US. The group has continued operating under the same banner anyway — either reconstituted affiliates or original members who weren't caught. That resilience is important context: law enforcement action against individual members hasn't functionally disrupted this threat actor.


## The Identity Data Problem That Doesn't Go Away


DMV records are a foundational layer for identity fraud. Unlike a leaked password — which gets reset — your name, date of birth, address history, and physical description don't change. A Florida driver's record purchased on a breach forum today is still accurate in five years. That permanence is what makes government identity databases such durable criminal assets.


Florida is also a particularly high-value target because of its demographics: large retiree population, high tourism throughput, significant immigrant community, and a history of insurance fraud operations — all populations with specific vulnerabilities to identity theft. A targeted 200,000-record pull against a specific demographic slice could be aimed at something more specific than a bulk resale.


Victims, if the data is confirmed real, have limited recourse. You can't freeze your DMV record the way you can freeze a credit file. Florida's data broker opt-out process under DPPA is narrow and enforcement is inconsistent. This is a problem that outlasts any single breach.


## What Defenders and Affected Individuals Can Do Now


For individuals: the immediate practical steps are monitoring-forward. Credit freeze all three bureaus now if you haven't already. Sign up for IRS Identity Protection PIN to block fraudulent tax filings. Watch for any Florida-related government correspondence that seems out of place — address changes, duplicate title requests, voter registration updates.


For state agencies and authorized DAVID users: if you're an organization with credentialed access to DAVID, this is the moment to audit your access logs. The question isn't just whether the Florida DHSMV systems were breached directly — it's whether a downstream authorized user's credentials were compromised. Third-party investigators, insurance companies, and repossession firms all have legitimate DAVID access, and each represents a potential entry point. That access chain is almost certainly longer than the state's security team can fully see.


---


## HackWire Analysis


The ShinyHunters DAVID claim fits a pattern that's accelerating: extortion actors targeting government identity infrastructure rather than corporate customer databases. The shift matters because government agencies operate on procurement timelines measured in years, not quarters. When a major retailer gets breached they can change vendors, rotate credentials, and roll out MFA broadly in months. A state DMV system has a different reality — legacy backend integrations, legislative budget cycles, and a sprawling authorized-user ecosystem that's genuinely difficult to secure uniformly.


What other coverage is missing here is the authorized-user attack surface. Every breach of a government database that requires credentialed access should immediately raise the question: was this a direct system compromise, or was a legitimate credential abused? The Snowflake campaign — where ShinyHunters was directly involved — showed exactly how devastating credential abuse against a shared infrastructure provider can be. DAVID has an analogous ecosystem of third-party authorized users. If one insurance fraud investigation firm with DAVID access had poor credential hygiene, the breach path might not touch Florida state systems at all.


The 200,000 record count also deserves more attention than it's getting. That's a suspiciously round number for a mass exfiltration. It suggests a query limit, an API cap, or a deliberate selection. If it's a query limit on the access interface, the attacker may have simply run out of time or bandwidth — meaning the total exposure could be larger. If it was deliberate selection, then someone knew what they were looking for. Neither interpretation is benign, and the forensic answer matters enormously for understanding how to close the hole.


Florida authorities need to be transparent here, not just to satisfy breach notification obligations, but because millions of residents whose data may be at risk deserve an answer faster than a government press release cycle typically delivers.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)