ShinyHunters, the extortion crew behind some of 2026’s biggest corporate data leaks, says it broke into a Florida state system that stores driver and vehicle records for millions of residents. As proof, the group posted a screenshot of a driver record belonging to Jeffrey Epstein, the late convicted sex offender, complete with his photo, signature, and personal details. The claim surfaced on the group’s dark web leak site on September 7, 2026, under a listing titled “State of Florida DMV,” and it comes with a deadline: pay up by September 11 or the files go public.
The state has not confirmed a breach. But the story is already spreading fast across security outlets, and it lands at a moment when ShinyHunters’ name has become shorthand for a wave of extortion attacks that have hit healthcare, retail, and now, apparently, government infrastructure. Here’s what’s confirmed, what’s still just an attacker’s claim, and why a stolen Epstein driving record became the proof point for a breach that could touch hundreds of thousands of Floridians.
What ShinyHunters Is Claiming
According to reporting from BleepingComputer, ShinyHunters says it compromised an online platform tied to DAVID, Florida’s Driver and Vehicle Information Database. DAVID is the internal lookup tool that Florida law enforcement and state officials use to pull driver history, vehicle registration, license transactions, addresses, insurance status, and parking permit records. It is not a public-facing consumer site. That distinction matters, because if the claim holds up, it means the attackers got inside a system meant only for verified government and law enforcement users, not a marketing database or a customer portal.
ShinyHunters told BleepingComputer it stole more than 200,000 driver records starting around September 3, 2026. The group’s account of how it got in centers on a password-reset flaw that it says let attackers take over multiple internal accounts, including ones belonging to DMV employees and, notably, an FBI agent. From there, the group claims it wrote a script to walk through record IDs sequentially, pulling down the HTML pages and images tied to each one. ShinyHunters also told the outlet it has since lost access to the system and believes the password-reset bug is being patched.
None of that account has been independently verified. Florida’s Department of Highway Safety and Motor Vehicles, listed by breach-tracking site BreachSense as the entity behind DAVID, had not issued a public confirmation as of this writing. Incident trackers, including DisclosureLens, are logging the Florida DMV listing as an unverified claim rather than a confirmed breach, which is the standard, appropriately cautious posture for a story that so far rests entirely on an attacker’s own telling.
Why the Epstein Record Became the Story
Data breach proof samples are usually mundane: a spreadsheet row, a redacted screenshot, a handful of email addresses. ShinyHunters picked something more attention-grabbing. The sample record the group posted belongs to Jeffrey Epstein and shows an expired driver record, according to Cybernews, along with his photo and signature. Reports describing the leaked screenshot say it also includes a Social Security number, driver’s ID number, a former address, physical descriptors, and vehicles on file under his name.
The choice of sample looks deliberate. A record tied to a name that still generates enormous public interest is far more likely to get picked up by journalists and shared widely than a random resident’s DMV file, and extortion groups know that press coverage pressures victim organizations faster than a quiet ransom note does. It’s a tactic ShinyHunters has leaned on before: pick a proof sample that guarantees headlines, then use the resulting attention as leverage in the extortion demand itself.
It’s worth being precise about what is and isn’t established here. Epstein died in 2019, so no living person’s current whereabouts or activity is exposed by an old driver record. What’s exposed, if the claim is accurate, is the kind of personally identifiable information, Social Security numbers, ID numbers, addresses, that would be damaging for any of the roughly 200,000 other people whose records ShinyHunters says it downloaded. The Epstein angle is a marketing hook for the extortion attempt. The actual harm, if the breach is real, falls on ordinary Florida drivers whose data sat in the same system.
The Leak Site Listing and the September 11 Deadline
Cybernews and other breach trackers describe the listing on ShinyHunters’ dark web site as short and formulaic, consistent with the group’s usual playbook: a title reading “State of Florida DMV,” a download link marked as a proof sample, and a message that reads, in the trackers’ reproduction, “Contact us, you know how, or we will release the files.” A “view download button below for proof” line accompanies the sample. Cybernews reports the group updated the listing with a “final warning” note around September 7, and multiple trackers cite a cutoff of September 11, 2026, for the threatened full release.
That four-day window is short even by extortion-gang standards, and it fits a pattern seen across ShinyHunters’ 2026 campaign: fast public disclosure, an aggressive deadline, and reliance on media coverage to do the pressuring rather than direct negotiation alone. Whether Florida’s DMV, or any state agency, engages with an extortion demand at all is a separate and consequential question. Government bodies generally have stricter no-negotiation postures than private companies, partly because ransom payments to hacking groups can carry legal and policy complications that a retailer or SaaS company doesn’t face.
Who Is ShinyHunters
ShinyHunters has been one of the most active extortion operations of the past two years, and BleepingComputer’s ongoing coverage of the group gives a sense of its range. The crew first built its reputation leaking large consumer databases for free on hacking forums, then pivoted toward higher-stakes corporate extortion. Earlier in 2026, the group launched a dedicated leak site to pressure companies hit in a wave of Salesforce-linked data theft incidents. In the weeks before the Florida DMV claim, BleepingComputer also reported ShinyHunters-linked activity tied to a breach affecting healthcare distributor McKesson and a confirmed breach at security company ADT, where the company told BleepingComputer the exposed data was limited to names, phone numbers, and addresses, with Social Security or Tax ID digits exposed in only a small percentage of cases.
The group also has a history that undercuts blind trust in its own claims. Earlier this year it stepped back from BreachForums, the hacking forum long associated with its leaks, calling it a waste of time following an FBI seizure of the platform in October 2025, and released a database of more than 300,000 BreachForums users on its way out. That track record shows a group willing to burn its own infrastructure and associates for a headline, which is part of why researchers treat the Florida DMV claim as unverified rather than dismiss it outright: ShinyHunters has been both credible and self-promotional in roughly equal measure.
What’s Confirmed vs. What’s Still an Attacker’s Claim
It’s easy for a story like this to blur into a single narrative of “Florida DMV hacked.” The individual facts deserve to be kept separate, because they carry very different weight.
| Claim | Status | Source |
|---|---|---|
| ShinyHunters posted a “State of Florida DMV” listing on its leak site | Confirmed (listing exists) | Cybernews, breach trackers |
| Sample includes Jeffrey Epstein’s DAVID driver record, photo, and signature | Confirmed (sample posted) | Cybernews, BleepingComputer |
| Sample data includes SSN, ID number, address, vehicle details | Reported by outlets reviewing the screenshot | Cybernews, BleepingComputer |
| 200,000+ driver records stolen since September 3, 2026 | Unverified attacker claim | ShinyHunters, via BleepingComputer |
| Breach method: password-reset flaw compromising DMV and FBI accounts | Unverified attacker claim | ShinyHunters, via BleepingComputer |
| Florida DMV/FLHSMV confirms a breach occurred | Not confirmed by the state | No official statement as of Sept. 8, 2026 |
| Leak deadline of September 11, 2026 | Confirmed (as stated in listing) | Cybernews, DisclosureLens |
That gap between “the listing exists” and “the breach is real” is where most of the uncertainty in this story lives. Extortion groups have every incentive to inflate record counts and dramatize their access, because a bigger number and a scarier method description both increase pressure on the named victim to pay before the deadline. At the same time, a sample built from a real, sensitive government record is a stronger form of proof than most leak-site claims manage, which is why security researchers aren’t dismissing it either.
Why a DMV Database Is a High-Value Target
State motor vehicle databases sit near the top of the target list for data thieves for a simple reason: the records they hold rarely change. A stolen credit card number gets canceled in days. A driver’s license number, date of birth, and Social Security number tied to a real address stay useful for identity theft and fraud for years, sometimes for a person’s entire adult life. DAVID reportedly gives access to license transaction history, prior addresses, insurance status, prior vehicle ownership, and parking permits, according to BleepingComputer’s description of the interface, which is a far richer profile of a person than most commercial breaches expose.
DMV systems also sit at an awkward intersection of scale and security investment. They serve tens of millions of transactions a year across counties, tag agents, insurers, and law enforcement, which means broad internal access by design, but state IT budgets for hardening and monitoring those systems often lag far behind what a bank or a major tech company spends on the same problem. A password-reset flaw, the exact vulnerability class ShinyHunters says it exploited, is a classic weak point in exactly this kind of sprawling, multi-stakeholder government system, where account recovery flows often predate modern identity verification standards.
How This Compares to Other 2026 ShinyHunters Incidents
The Florida DMV claim doesn’t stand alone. It’s the latest entry in a year where ShinyHunters and closely associated extortion crews have hit a wide range of sectors, each with a different scale and a different level of confirmation.
| Incident | Sector | Claimed/Reported Scale | Confirmation Status |
|---|---|---|---|
| Florida DMV (“DAVID” database) | State government | 200,000+ driver records (claimed) | Unconfirmed by the state |
| ADT | Home security | Names, phone numbers, addresses; SSN/Tax ID digits in a small share of cases | Confirmed by ADT |
| Salesforce-linked customer data leaks | Multiple enterprises | Multiple companies’ customer databases | Confirmed across several named victims |
| BreachForums user database | Hacking forum | 300,000+ user records | Confirmed (self-leaked by ShinyHunters) |
The pattern across these incidents is consistent: ShinyHunters moves fast between very different kinds of targets, mixes confirmed and unconfirmed claims in its public messaging, and consistently uses a dark web leak site with a countdown clock as its main pressure tool. A state government agency is a new type of target in that list, and if the DMV claim is verified, it would mark one of the group’s first confirmed intrusions into government infrastructure rather than corporate or consumer platforms.
The Password-Reset Flaw Pattern
If ShinyHunters’ account is accurate, the entry point wasn’t a zero-day exploit or a sophisticated supply chain attack. It was a weakness in how the system verified a user’s identity during a password reset, a category of bug that shows up again and again in breach postmortems because it’s boring to test and easy to get wrong. A password-reset flow that accepts a weak secondary verification, like a security question or an email link without proper expiration, can let an attacker take over an account without ever touching a password hash or bypassing multi-factor authentication directly.
The claim that compromised accounts included both DMV employees and an FBI agent, if true, points to a system where internal and law enforcement users share the same authentication infrastructure and the same reset mechanism. That’s a common design choice for cost and simplicity, but it means a single flaw in one reset flow can expose credentials across very different classes of users with very different levels of access, from routine registration lookups to sensitive law enforcement queries.
What Florida Drivers Should Watch For
Given the breach remains unconfirmed, there’s no official notification process underway yet, and residents shouldn’t expect a state-issued breach letter until, or unless, FLHSMV confirms an incident. That said, if the underlying claim is accurate, the exposed data profile, Social Security numbers, driver’s license numbers, physical addresses, and vehicle ownership records, maps closely onto the information needed for identity theft, fraudulent loan applications, and SIM-swap attacks that rely on knowing a target’s address history.
Security practitioners generally recommend the same baseline response regardless of official confirmation timing: monitor credit reports for unfamiliar accounts, watch for unexpected DMV or insurance correspondence, and be skeptical of any unsolicited call or email referencing a driver’s license number, since that detail alone is no longer a reliable way for a legitimate caller to prove their identity if this data is genuinely circulating. Freezing credit with the major bureaus remains the most concrete step available to individuals before an official notification process, if any, begins.
Market and Industry Impact
Government breach claims move differently than corporate ones in the security industry. There’s no stock price to react, but state agencies face their own version of market pressure: legislative scrutiny, procurement reviews, and pressure on whichever vendor built or maintains the DAVID platform. Motor vehicle database software is typically built and maintained by a small pool of government IT contractors across US states, so a confirmed breach in Florida would likely trigger security reviews of similar DMV platforms in other states running comparable systems, echoing how a single vendor flaw in one state’s unemployment insurance portal during past incidents prompted multi-state audits.
For the broader extortion economy, a claimed government breach also raises the reputational stakes for ShinyHunters itself. Corporate victims sometimes negotiate quietly. Government agencies rarely can, both for legal reasons and because taxpayer-funded ransom payments invite exactly the kind of press scrutiny the group is counting on. That dynamic could cut either way: it might pressure Florida to respond fast to avoid a drawn-out news cycle, or it might mean the state simply refuses to engage at all, in which case the September 11 deadline passes with a full data dump rather than a resolution.
Historical Context: Government Data Breaches Aren’t New
State and federal government systems have been breach targets for well over a decade, and DMV-style databases have proven especially attractive because of how long the underlying personal data stays valid. What makes the Florida DMV claim notable within that history isn’t the target type, it’s the extortion-first approach: rather than quietly selling the data on a criminal forum, ShinyHunters went straight to public pressure with a named victim, a graphic proof sample, and a countdown, following the same leak-site playbook the group has refined across its corporate campaigns this year. That represents an evolution in tactics against government targets specifically, which have historically seen slower, quieter disclosure processes compared to the private sector.
What Happens Next
Three things determine how this story develops over the next week. First, whether FLHSMV or another Florida state authority issues any public statement, confirming, denying, or declining to comment on the breach claim. Second, whether the September 11 deadline passes with ShinyHunters actually releasing a larger data dump, which would move this from “claim” to “confirmed incident” regardless of what the state says. Third, whether other security researchers or journalists who receive the full sample can independently verify record authenticity beyond the single Epstein screenshot currently circulating.
Predictions
- Florida’s DMV or a state cybersecurity office will likely issue at least an initial acknowledgment or denial within days of the September 11 deadline, given the media attention the Epstein sample has already generated.
- If the breach is confirmed, expect other states running similar motor vehicle database platforms to order internal security reviews of their own password-reset and account-recovery flows within the following weeks.
- ShinyHunters will likely continue picking high-profile proof samples for future claims, since the Epstein record has already driven significant press coverage relative to a routine breach announcement.
- Regardless of whether Florida pays, expect the group to publish at least a partial data sample beyond the single Epstein record if the deadline passes without resolution, consistent with its pattern on prior leak-site campaigns.
- This incident will likely renew calls, at both state and federal level, for stronger identity-verification standards on government account recovery systems, an area that has lagged well behind private-sector practices.
Frequently Asked Questions
Is the Florida DMV breach confirmed?
No. As of September 8, 2026, the claim comes solely from ShinyHunters and has not been confirmed by the Florida Department of Highway Safety and Motor Vehicles or any other state authority. Breach-tracking sites including DisclosureLens list it as an unverified claim.
What is the DAVID database?
DAVID stands for Driver and Vehicle Information Database, an internal Florida system used by law enforcement and state officials to look up driver history, vehicle registration, license transactions, addresses, insurance status, and related records.
Why did ShinyHunters use Jeffrey Epstein’s record as proof?
Reports from Cybernews and BleepingComputer indicate the group selected Epstein’s expired driver record, including his photo and signature, as the sample proof attached to its leak-site listing. The choice appears designed to maximize media attention and pressure on the named victim rather than to expose anything new about Epstein himself.
How many records does ShinyHunters claim to have stolen?
The group told BleepingComputer it obtained more than 200,000 driver records starting around September 3, 2026. This figure comes directly from the attackers and has not been independently verified.
What is the deadline for the data to be released?
Multiple breach trackers, including Cybernews, cite a deadline of September 11, 2026, for ShinyHunters to release the full dataset if its extortion demand isn’t met.
What should Florida residents do right now?
Since no official notification has been issued, there’s no confirmed action required yet. As a general precaution against identity theft, security practitioners recommend monitoring credit reports, watching for unexpected DMV or insurance-related contact, and considering a credit freeze with major bureaus.
Who is ShinyHunters?
ShinyHunters is an extortion group that has been linked to numerous high-profile data leaks and breaches throughout 2025 and 2026, including a leak site tied to Salesforce-linked customer data theft, a confirmed breach at ADT, and a self-published database of over 300,000 BreachForums users after the group stepped away from that platform following an FBI seizure in October 2025.
How did the attackers claim to gain access?
ShinyHunters told BleepingComputer it exploited a password-reset flaw that allowed it to compromise multiple internal accounts, including those belonging to DMV employees and an FBI agent, then used those accounts to iterate through driver records by ID. This account has not been independently verified.



