Florida DMV DAVID System Breach Analysis: Credential Misuse and ShinyHunters Extortion Incident September 2026

Florida DMV DAVID System Breach Analysis: Credential Misuse and ShinyHunters Extortion Incident September 2026

Executive Summary

On September 4, 2026, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) discovered a breach of its DAVID (Driver and Vehicle Information Database) system. The breach was attributed to the use of compromised credentials belonging to a Plant City Police Department user, which were improperly stored on a personal device. The ShinyHunters extortion group claimed responsibility, stating they accessed over 200,000 driver records, though this number remains unconfirmed by FLHSMV. The breach was publicly confirmed on September 11, 2026, and mitigation steps were taken immediately (BleepingComputer, 2026-09-11, Shattered.io, 2026-09-11). The official investigation is ongoing, and further details, including the exact number of affected records and the nature of the data accessed, are pending.

Technical Information

The breach of the DAVID system was executed through credential misuse, specifically via credentials belonging to a Plant City Police Department user that were improperly stored on a personal electronic device. This allowed unauthorized access to the DAVID database, which contains sensitive driver and vehicle information for Florida residents.

Attack Vector Analysis

The initial access vector was the use of valid credentials (MITRE ATT&CK T1078: Valid Accounts, https://attack.mitre.org/techniques/T1078/) that had been improperly stored on a police officer’s personal device (T1555: Credentials from Password Stores, https://attack.mitre.org/techniques/T1555/). FLHSMV confirmed that the credentials were stored on a personal device and used for unauthorized access (BleepingComputer). The confidence level for this vector is high, as it is based on direct statements from FLHSMV.

Alternative claims were made by the ShinyHunters group, who stated they exploited a password reset flaw to access multiple DAVID accounts, including those of DMV employees and an FBI agent. However, FLHSMV has not confirmed this method, and there is no technical evidence supporting it. The confidence level for this claim is low, as it is unverified and not corroborated by primary sources.

Once inside the system, the attacker reportedly iterated through DAVID record IDs and downloaded associated HTML pages and images. This aligns with MITRE ATT&CK T1213.006: Data from Information Repositories: Databases (https://attack.mitre.org/techniques/T1213/006/). The confidence level for this activity is medium, as it is based on threat actor claims and sample data, but not confirmed by FLHSMV.

Specific Malware and Tools Identified

No specific malware or custom tools were identified in this incident by FLHSMV or public reporting. The attack relied on credential misuse rather than malware deployment. This is supported by the absence of malware or tool indicators in official statements and reporting (BleepingComputer, Shattered.io). The confidence level for this assessment is high.

Historically, ShinyHunters has used tools such as MeshCentral, ConnectWise, WinSCP, and custom scripts for lateral movement and data exfiltration (MITRE ATT&CK G1057). However, there is no evidence these tools were used in the Florida breach, so the confidence level for their involvement in this incident is low.

Historical Context of Threat Actor Activities

ShinyHunters (MITRE ATT&CK G1057) has been active since at least 2019, specializing in credential theft, data extortion, and resale of personally identifiable information (PII). The group is known for targeting cloud platforms, SaaS, and state/local government entities. ShinyHunters is associated with other threat groups such as The Community (The Com), Scattered Spider, and LAPSUS$. Their tactics, techniques, and procedures (TTPs) include credential theft (T1078, T1555, T1552.001), exploitation of public-facing applications (T1190), use of remote access tools (T1219), data exfiltration via web services (T1567), and social engineering and phishing (T1598, T1684) (MITRE ATT&CK G1057).

Sector-Specific Targeting Patterns

The Florida DMV breach is part of a broader pattern of credential-based attacks in 2026 targeting state agencies and critical infrastructure (Shattered.io). Risks highlighted by this incident include improper credential storage, lack of device management, and interagency access to sensitive databases. The confidence level for this assessment is high, as it is corroborated by sector reporting and official statements.

Technical Details of Attack Methods Mapped to MITRE ATT&CK

The following MITRE ATT&CK techniques are relevant to this incident:

  • T1078: Valid Accounts (use of stolen police credentials)
  • T1555: Credentials from Password Stores (improper storage on personal device)
  • T1133: External Remote Services (remote access to DAVID system)
  • T1213.006: Data from Information Repositories: Databases (iterating through DAVID records)
  • T1567: Exfiltration Over Web Service (if data was exfiltrated via web protocols)

There is no evidence of malware, remote code execution, or exploitation of software vulnerabilities in this incident. The confidence level for this assessment is high.

Attribution Confidence

Attribution to ShinyHunters is based on public claims, screenshots, and extortion attempts. The TTPs (credential theft, data extortion, targeting of government databases) are consistent with ShinyHunters’ historical activity (MITRE ATT&CK G1057). However, there is no direct technical artifact linking ShinyHunters to the breach in official disclosures. The confidence level for attribution is medium.

Summary Table: MITRE ATT&CK Mapping for Florida DMV Breach

MITRE ID

Technique Name

Evidence Type

Confidence

Source

 

T1078

Valid Accounts

Technical

High

https://attack.mitre.org/techniques/T1078/

T1555

Credentials from Password Stores

Technical

High

https://attack.mitre.org/techniques/T1555/

T1133

External Remote Services

Technical

High

https://attack.mitre.org/techniques/T1133/

T1213.006

Data from Info Repositories: DBs

Pattern/Circumstantial

Medium

https://attack.mitre.org/techniques/T1213/006/

T1567

Exfiltration Over Web Service

Circumstantial

Medium

https://attack.mitre.org/techniques/T1567/

Affected Versions & Timeline

The affected system is the DAVID (Driver and Vehicle Information Database) operated by FLHSMV. The breach was discovered on September 4, 2026, and publicly confirmed on September 11, 2026. The credentials used for unauthorized access belonged to a Plant City Police Department user and were improperly stored on a personal device. The exact number of records accessed or stolen has not been confirmed by FLHSMV. The breach was quickly mitigated, and no further unauthorized access is believed to be ongoing as of the latest disclosures (BleepingComputer, 2026-09-11, Shattered.io, 2026-09-11).

Threat Activity

The ShinyHunters extortion group claimed responsibility for the breach, stating they accessed over 200,000 driver records. They also claimed to have exploited a password reset flaw to gain access to multiple DAVID accounts, including those of DMV employees and an FBI agent. However, FLHSMV has only confirmed that the breach was due to credential misuse and has not validated the record count or the authenticity of any sample data provided by the threat actors. The group reportedly iterated through DAVID record IDs and downloaded associated HTML pages and images. The incident is consistent with ShinyHunters’ historical focus on credential theft and data extortion.

Mitigation & Workarounds

The following mitigation and workaround recommendations are prioritized by severity:

Critical: Immediately audit and revoke any credentials that have been improperly stored or are suspected to be compromised, especially those with access to sensitive databases such as DAVID. Enforce multi-factor authentication (MFA) for all remote and privileged access to critical systems.

High: Implement strict policies prohibiting the storage of credentials on personal or unmanaged devices. Conduct mandatory security awareness training for all personnel with access to sensitive systems, emphasizing credential hygiene and device management.

Medium: Review and update incident response plans to ensure rapid detection and containment of credential misuse incidents. Regularly monitor access logs for anomalous activity, particularly from accounts with elevated privileges or remote access.

Low: Periodically review and update interagency access controls to minimize unnecessary exposure of sensitive databases. Encourage ongoing collaboration with state and federal law enforcement agencies to share threat intelligence and best practices.

Indicators of Compromise

No public indicators of compromise were available at the time of writing. All organizations are advised to validate any future indicators before enforcement.

References

https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/ (Published September 11, 2026)

https://shattered.io/florida-dmv-breach-disclosure-timeline-2026/ (Updated September 11, 2026)

https://attack.mitre.org/groups/G1057/ (MITRE ATT&CK ShinyHunters Group Profile)

https://attack.mitre.org/techniques/T1078/ (Valid Accounts)

https://attack.mitre.org/techniques/T1555/ (Credentials from Password Stores)

https://attack.mitre.org/techniques/T1133/ (External Remote Services)

https://attack.mitre.org/techniques/T1213/006/ (Data from Information Repositories: Databases)

https://attack.mitre.org/techniques/T1567/ (Exfiltration Over Web Service)

About Rescana

Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor risks related to external vendors and partners. Our platform enables continuous monitoring of credential exposure, policy compliance, and supply chain vulnerabilities, supporting proactive risk mitigation for incidents involving credential misuse and unauthorized access. For more information or to discuss your organization’s risk posture, please contact us at info@rescana.com.