Florida DMV data breach (2026): what was exposed and what to do

Updated Corrections

September 16, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

What happened

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a breach of DAVID, its Driver and Vehicle Information Database. In a September 11, 2026 statement, the agency said an international cybercriminal organization used the credentials of a single Plant City Police Department user, which had been improperly stored on that employee's personal electronic device. FLHSMV said it learned of the breach on September 4, 2026, that it was quickly mitigated, and that no further breach has occurred or is ongoing. It notified the Florida Attorney General's office and is working with the Florida Digital Service and the Florida Department of Law Enforcement.

The ShinyHunters extortion group listed the agency on its leak site on September 7 and told BleepingComputer it had taken more than 200,000 driver records through a password-reset flaw. The state's account points to a single stolen login instead.

After a ransom deadline passed, the group published the data. Straight Arrow News reported on September 14 that the archive held more than half a million documents, of which 475,207 were images and 119,494 were downloaded pages of individual driving records. On September 16, TechCrunch reported that the hackers published the files "because the victim did not pay a ransom," and said the copy it reviewed held hundreds of thousands of vehicle ownership certificates carrying buyers' and sellers' names and addresses along with vehicle identification numbers. A smaller group of files, TechCrunch wrote, "included Social Security numbers and other government-issued documents, such as non-U.S. passports and immigration papers but did not appear to contain driver's licenses or people's photos." Straight Arrow News, reviewing the archive two days earlier, described license photos and signatures as abundant in it. An agency spokesperson did not answer TechCrunch's request for comment.

FLHSMV has not said how many people are affected. Every record and file count here comes from the attackers or from press review of the leaked archive, not from the state.

Sources

What data was exposed

The following types of personal data were compromised:

  • Driver and vehicle records from DAVID (confirmed by FLHSMV, which has not published a field list)
  • Names, home addresses, dates of birth, and Social Security numbers (in attacker samples and in press review of the leaked archive)
  • Driver's license numbers, issue and expiration dates, and vehicle details (in attacker samples)
  • Vehicle ownership certificates with buyers' and sellers' names and addresses and vehicle identification numbers (TechCrunch, describing the bulk of what it reviewed)
  • Government-issued documents such as non-U.S. passports and immigration papers, in a smaller set of files (TechCrunch); Straight Arrow News also described permanent resident cards, visas, employment authorization cards, and refugee travel documents
  • Driver's license photos and signatures (Straight Arrow News, which called them abundant in the archive; TechCrunch wrote that the smaller set of files it describes did not appear to contain licenses or photos)
  • Driving history, including DUI records (Straight Arrow News)

The two press reviews of the same archive don't line up exactly on license photos, and FLHSMV has published no field list of its own, so treat the list above as what each outlet reported rather than a settled inventory.

Breach details

Detail Value
Breach name Florida DMV (DAVID)
Date September 3 to 4, 2026
Disclosed September 11, 2026 (FLHSMV statement); data published September 14, 2026
Accounts affected Not disclosed
Domain flhsmv.gov

This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by the Florida Department of Highway Safety and Motor Vehicles; it reflects a publicly reported security incident.

For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.

What to do now

Based on the data exposed in this breach, here are the steps you should take:

  • If you hold a Florida driver's license or ID, or bought or sold a vehicle in Florida, place a free credit freeze with Equifax, Experian, and TransUnion. Press reviews of the leaked files describe Social Security numbers alongside license and vehicle ownership details for at least some records.
  • Be skeptical of "DMV," toll, title, or registration messages that use your real name, plate, VIN, or address. Go to flhsmv.gov directly or call a number printed on official mail.
  • Review your credit reports and bank statements for new accounts you did not open.
  • If you find fraud, report it at IdentityTheft.gov and keep the recovery plan it generates.
  • Watch for mail or phone scams that use accurate vehicle or address details to pressure you into paying fake fees.

Did the Florida DAVID story mean my licence photo is public, or that Delist covers the DMV database?

No on both. This page cannot tell you whether your DAVID record was included; rely on official notices rather than a tracker. FLHSMV confirmed unauthorised access through stolen credentials, and the record and photo counts come from attackers or press review, not a state victim list. A government driver database is not the same thing as a people-search listing.

Frequently asked questions

Can Delist remove my record from DAVID, FLHSMV, or this dump?

No, and nobody selling that promise can. Delist helps with open-web listings, meaning people-search and related surfaces, not state motor vehicle systems or leaked archives.

What's the difference between this breach and people-search sites?

DAVID is a government driver and vehicle database that was accessed improperly. People-search sites publish findable profiles assembled from public and commercial sources. A free scan checks open-web exposure (signals are not listings); it is not a membership check of DAVID or this dump.

I have a Florida licence. What should I do first?

Verify any notice through official FLHSMV channels. If Social Security or ID numbers may be involved, freeze your credit at the three bureaus, and watch for phishing that uses your plate, VIN or address.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.