The Florida DAVID story moved from confirmed access to a public dump.
On September 16, 2026, TechCrunch reported that the ShinyHunters extortion group published hundreds of thousands of files stolen from Florida’s DAVID (Driver and Vehicle Information Database). The group said it published because “the victim did not pay a ransom or cooperate and comply.” An FLHSMV spokesperson did not respond to TechCrunch’s request for comment on the published set.
TechCrunch says it reviewed a copy of the stolen data: the bulk looks like certificates of vehicle ownership with owners’ names, buyer/seller addresses, and VINs. A smaller subset included Social Security numbers and other government-issued documents such as non-U.S. passports and immigration papers. TechCrunch reports the set did not appear to contain driver’s licenses or people’s photos. The official record count is Undisclosed; FLHSMV has still not published how many records were accessed.
Context still stands from the agency’s September 11 statement: FLHSMV learned of the breach on September 4, attributed access to compromised Plant City Police Department credentials stored on a personal device, said the breach was mitigated with no ongoing access, and notified the Florida Attorney General. ShinyHunters’ earlier 200k+ claim remains an attacker number only. No reconciled victim tally from the leak site.
POV: state DMV trust-broker databases are now leak-site inventory when ransom is refused — not only a credential-hygiene memo. Underwrite TechCrunch’s observed file types + FLHSMV’s Sep 11 access path. Exact victim counts remain Undisclosed until the state prints one.
