Florida DAVID breach leads to publication of vehicle ownership records

ShinyHunters has published hundreds of thousands of files it says were taken from Florida’s DAVID database, a state system containing vehicle and driver information. Florida’s Department of Highway Safety and Motor Vehicles, known as FLHSMV, confirmed a breach after attackers obtained a police officer’s credentials that had been stored on a personal device.
The group said it breached DAVID earlier in September and released the material after the victim allegedly failed to pay a ransom or meet its demands. As purported proof of access, the attackers posted a screenshot of a record associated with the late sex offender Jeffrey Epstein, who had lived in Florida.
What the published files contain
A copy of the stolen data reviewed by TechCrunch contained hundreds of thousands of certificates of vehicle ownership. Those records included vehicle owners’ names, the addresses of buyers and sellers, and vehicle identification numbers, or VINs.
A smaller set of files contained Social Security numbers and government-issued documents, including non-US passports and immigration papers. The materials reviewed did not appear to contain driver’s licences or photographs of individuals.
The incident therefore extends beyond vehicle records alone. Names, addresses, VINs and identity documents can expose affected people to privacy risks and can complicate verification processes for organisations that rely on customer or vehicle information.
Credential handling is central to the incident
FLHSMV linked the breach to police credentials stored on a personal device. The confirmed detail puts credential storage and access control at the centre of the incident, rather than suggesting that the database was accessed through a disclosed software flaw.
The publication also follows another driver-identity incident reported this month: a breach at identity-verification company IDScan in which hackers stole more than 150 million images of driver’s licences. The two incidents show the volume and sensitivity of records concentrated in systems used for identity and transportation administration.
Business implication
Organisations with access to identity, vehicle or public-sector data should review whether privileged credentials can reside on personal devices, limit access to the records required for each role, and ensure incident plans address the exposure of ownership and identity documents.

