Florida DMV Data Breach: What ShinyHunters Published, and What to Do Now

Florida DMV Data Breach: What ShinyHunters Published, and What to Do Now

A man in Tampa sold his truck in March. On Wednesday, his name, his old address, the buyer’s address and the truck’s VIN were in a folder that anyone with a browser could download, because a group called ShinyHunters asked the State of Florida for money and the state did not pay. He did nothing wrong, he has no account to reset, and there is no one to call. That is what the Florida DMV breach is: a state record you did not choose to create, now in the hands of people who sell records.

Confirmation: confirmed by the agency. The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) says it learned of the breach on 4 September 2026. The record count and the exact contents are the attackers’ claims, reported by TechCrunch and BleepingComputer, and not yet confirmed by the state.

What happened

On 16 September 2026, the ShinyHunters extortion group published hundreds of thousands of files taken from Florida’s driver and vehicle database after saying the state “did not pay a ransom or cooperate and comply.” That is TechCrunch’s account of the leak, which it reviewed.

The story is eight days old. On 8 September, BleepingComputer reported that ShinyHunters claimed to have broken into DAVID, the Driver and Vehicle Information Database that Florida police officers and officials use to look up any driver in the state. The group said it got in around 3 September through compromised accounts belonging to DMV employees and an FBI agent, and posted a screenshot of Jeffrey Epstein’s DAVID record as proof, showing an address, a Social Security number, a birth date, a licence number and registered vehicles. It claimed more than 200,000 records.

On 10 September, FLHSMV confirmed it. Its statement, reported by WCTV and BleepingComputer: “On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization. The data breach was quickly mitigated and no further breach has occurred or is ongoing.” The Florida Department of Law Enforcement is working the case, and the Attorney General’s office was notified as state law requires. On 11 September the agency said how it happened: the attacker used “compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee’s personal electronic device.” One officer’s saved password, on one personal device, was the front door.

The state has not said how many people are affected, what fields were taken, or whether it will write to them. It did not respond to TechCrunch about the published files.

What was exposed

What TechCrunch saw in the published files is mostly vehicle-title records: the names of buyers and sellers, their addresses, and vehicle identification numbers, with a smaller set of records carrying Social Security numbers and government documents such as non-US passports and immigration papers. Driver’s licence photos are not reported as included. DAVID itself holds more than that, per BleepingComputer: Social Security numbers, licence numbers, addresses, birth dates, issue and expiry dates, insurance and registered vehicles. What is in the leak and what is in the database are two different questions, and only the state can answer the second one.

Here is what each reported item is worth to the person holding it:

  • Name and home address. Enough to write to you, to find you, and to pass as the DMV in a letter, a text or an email that quotes your street.
  • VIN and the vehicle record. Enough to make the fake “unpaid toll” or “registration hold” notice name your actual car. A scam that gets the make and plate right is a different thing from one that does not.
  • Buyer and seller pairs. A seller can be told a buyer is disputing the title; a buyer can be told the seller’s lien was not cleared. Both stories fit the record.
  • Social Security number, where present. The one item that does not expire. With a name, address and birth date it is enough to open credit, and no Florida agency can issue you a new one.
  • Immigration and passport documents, where present. For the people in that subset, the exposure is not fraud. It is a folder that tells anyone who downloads it what their status is.

No email addresses are reported in the files, and no passwords: this was not an account breach at the drivers’ end. The password that was stolen belonged to a police officer.

What to do now

Most of this is about your credit and your phone, not about OptMsg, and the first step matters more than the rest put together.

1. Freeze your credit at all three bureaus — Equifax, Experian and TransUnion. It is free, it takes ten minutes each, and it turns a leaked Social Security number into a number that cannot open an account. Thaw it when you apply for something; refreeze after. If you have children with Florida records in your household, freeze theirs too. 2. Treat any DMV, toll or “license suspended” message as fake until you have checked it yourself. Florida does not text you to collect a fee. Go to flhsmv.gov by typing it, or your county tax collector’s site, and look at your own record there. Do not click, do not reply, do not call the number in the message. 3. Watch the mail and the phone as much as the inbox. The leak has your street, not your email. The next move is a letter that looks official, or a call from “the DMV” or “the FDLE” that knows your car. Hang up and call back on a number you found yourself. 4. Pull your free credit reports at annualcreditreport.com and look for accounts you did not open. Do it again in three months. 5. If your immigration documents may be in the file, talk to an immigration attorney or a legal-aid clinic before anyone contacts you about them, not after. 6. Turn on the strongest sign-in your email account offers. Your email is where every account you own gets reset. A passkey where available, an authenticator app otherwise. This breach did not touch it; the next one will try to.

How OptMsg changes this exposure

Honestly, and at its real size: OptMsg would not have prevented this. The data came out of a state system through a police officer’s saved password, and nothing you choose about your own inbox changes what Florida keeps on you or how it protects it. The leak did not include email addresses, so what an opt-in inbox changes here is narrower than in most breaches, and it is worth saying exactly what it is.

It is the wave that follows. Every big breach is followed by messages dressed as the victim: “your Florida license has been suspended, pay the reinstatement fee”, “your vehicle registration is on hold”, “unpaid toll, final notice”. Those messages go to everyone the scammers can reach, not only the people in the file, and a headline about a DMV breach is what makes them land. Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. With OptMsg’s patent-pending opt-in technology, the email from flhsmv-notice.com lands in Trash, not in front of you with your car’s make in the subject line. Only people you approve can reach your inbox. Everyone else goes to Trash. And if a message in Trash comes from a sender many other OptMsg users have opted in to, you get a push alert, so a real notice is not lost.

There is a second point, and it is about design rather than this leak. The DAVID breach began with a password stored where it should not have been. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. There is no saved password on the account for anyone to find on a personal device, and nothing from a breach elsewhere to try against it.

What that does not cover: the text message, which is the route this leak is built for; the letter and the phone call; a phishing page you open yourself; a message from a sender you did approve whose own account was taken; a compromised device; or someone with your unlocked phone. Those are the six steps above, and the first three are the whole defence against the text, the letter and the call.

If you want an inbox where the fake suspension notice cannot get in front of you, see how Simple by Design works, or read why your inbox should not care about a leaked password.

Ready for an inbox that only holds the mail you asked for? Create Your Account.

Your Inbox. Your Rules.

Frequently asked questions

What happened in the Florida DMV data breach? Florida’s Department of Highway Safety and Motor Vehicles confirmed that on 4 September 2026 it learned of a breach of DAVID, the database police and officials use to look up drivers, through a Plant City police officer’s credentials stored on a personal device. The ShinyHunters group claimed more than 200,000 records and published hundreds of thousands of files on 16 September after saying the state did not pay.

What information was exposed in the Florida DMV breach? The published files reviewed by TechCrunch are mostly vehicle-title records: names, buyer and seller addresses and VINs, with a smaller subset holding Social Security numbers and immigration or passport documents. Licence photos are not reported. The state has not confirmed the contents.

How do I know if I am affected by the Florida DMV breach? Right now you cannot. FLHSMV has not published a count or said whether it will notify people. If the dataset is loaded into Have I Been Pwned you can check there, but the files are not reported to contain email addresses, so the useful steps are a credit freeze and a hard rule about DMV messages.

Was my email or password stolen in the Florida DMV breach? No email addresses and no driver passwords are reported in the leak. The stolen password belonged to a police officer. The risk to you is a convincing fake DMV notice and, for people whose SSN is in the file, identity fraud.

Would OptMsg have stopped the Florida DMV breach? No. It happened inside a state system. What OptMsg changes is the aftermath: mail from a sender you have not approved goes to Trash rather than your Inbox, so the fake “license suspended” email built on this headline has a shorter path.

Sources

Scroll to Top