TTO-2026-0908-111 · September 8, 2026 Unconfirmed ClaimData Breach

ShinyHunters Claims Breach of Florida DAVID Driver Database — 200,000 Records, September 11 Deadline

flhsmv.govShinyHuntersDAVID database200,000 records claimedPassword-reset flawFLHSMV not confirmed

Summary

The ShinyHunters extortion group claims it breached Florida's Driver and Vehicle Information Database, managed by the Florida Department of Highway Safety and Motor Vehicles, and extracted more than 200,000 driver records. The group published a listing on its dark web leak site on September 7, including a screenshot it asserts shows a record for deceased convicted sex offender Jeffrey Epstein as proof of access. ShinyHunters told BleepingComputer it exploited a password-reset flaw in the DAVID platform to compromise multiple accounts, including DMV employees and an FBI agent. FLHSMV has not confirmed a breach, unauthorized access, or data theft. The group set a September 11, 2026 deadline for the agency to make contact.

Timeline

DateEvent
~Sep 3, 2026ShinyHunters claims exfiltration began via password-reset flaw; access lost after flaw was patched
Sep 7, 2026ShinyHunters publishes DAVID listing on dark web leak site with purported Epstein record; updates with final warning
Sep 8, 2026BleepingComputer reports; FLHSMV has not confirmed a breach or responded publicly
Sep 11, 2026ShinyHunters-stated deadline for FLHSMV to make contact before alleged data release

What the Evidence Supports

ShinyHunters has a well-documented history of substantiated breach claims, and the group provided specific technical detail about the alleged attack vector — a password-reset flaw enabling account takeover — consistent with the type of access-control failure that has produced real breaches in prior incidents. The purported Epstein record screenshot has not been independently forensically verified as authentic, and FLHSMV has not confirmed any incident.

The evidentiary situation as of this publication: a credible threat actor has made a specific claim with supporting documentation; an attack vector has been described; the target agency has not confirmed or denied; and no independent forensic review of the sample data has been published. The claim should be treated as credible but unconfirmed. DAVID is an authorized-access system used by law enforcement and government agencies to look up Florida driver and vehicle records, meaning the exposed data, if real, includes names, addresses, Social Security numbers, driver license images, and vehicle information for Florida residents.

Domain Intelligence

flhsmv.gov — 85.0

flhsmv.gov scores at 85.0, above the high-trust threshold, with a single routine canonical-signal marker and no adverse flags. This is consistent with established government domain posture. The score reflects accumulated evidence about the domain over time and does not incorporate the unconfirmed ShinyHunters claim, which has not been verified by independent forensic sources or acknowledged by the agency. A high score and an unconfirmed breach claim can coexist — this is structurally similar to the situation documented in TTO-2026-0905-098.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026