ShinyHunters Proved a Florida Police-DMV Breach With an Epstein Record. Twenty-Two DAVID Printouts Have Been Public Since 2019 — Including Ghislaine Maxwell's, Timestamped to the Second.
ShinyHunters says it took two hundred thousand records out of DAVID — Florida's Driver and Vehicle Information Database, the system a police officer queries when they want to know who they just pulled over. The group says access came through a password-reset exploit and then through accounts belonging to FBI personnel who hold state portal credentials. Exfiltration started around 3 September and ended when somebody patched the flaw. The leak deadline is 11 September. As of yesterday the Florida Department of Highway Safety and Motor Vehicles had confirmed nothing.
To prove they had been inside, they published a DAVID record for Jeffrey Epstein.
We host four hundred thousand documents from the DOJ Epstein releases and we run a threat-intel corpus on the same infrastructure, which makes this one of the few desks where those two facts land on the same table. So we went and looked.
There are twenty-two DAVID pages sitting in the public Epstein files. Not summaries. Not references. Actual printouts from david.flhsmv.gov, three of them still carrying the live deep-link path /DAVID/Customer/CustomerDetailsPF/.
What a DAVID query actually returns
Document EFTA00037657, present in three separate DOJ datasets, is the record of Ghislaine Noelle Maxwell. Time printed: 12/10/2019, 9:45:51 AM. Somebody with a badge ran her at a quarter to ten on a Tuesday morning and printed the result, and the print job kept the second hand.
The page gives her licence status, class, original issue date of 19 February 1993, the 2012 issue, the 2017 replacement, the 2020 expiry, date of birth, gender, height, race, citizenship, country of birth, prior DUI and driving-while-licence-suspended counts, a home address on Venetian Way in Miami Beach down to the apartment number, and labelled fields for the licence number and social security number.
That is one record. ShinyHunters says it has two hundred thousand of them.
Anybody arguing about whether this data is sensitive should read the field list again and then consider that the system exists so a patrol officer can pull it up at the roadside.
The proof authenticates instantly and proves the least
Here is the awkward part for the extortionists.
Epstein's DAVID record is a superb choice if what you want is recognition. Every journalist on earth can confirm at a glance that the man existed, lived in Palm Beach, and held a Florida licence. Nobody has to take your word for anything. It is the cybercrime equivalent of asking Michael Quirke to authenticate a carving — the one witness whose recognition nobody will question.
It is a poor choice if what you want is evidence, and for exactly the same reason. Epstein is the most documented private citizen in the modern American record. His files have been released, re-released, OCR'd, mirrored and indexed by more parties than anyone can count, and DAVID printouts are demonstrably among them. We are looking at twenty-two right now.
So the single record they chose to prove a September 2026 intrusion belongs to the one document class already available to anybody who downloaded a DOJ dataset in 2019 and knew what to grep for.
Read that carefully, because it cuts one way only. This is not proof that ShinyHunters is lying. It is proof that their proof is weak. A DAVID printout of Epstein is consistent with a fresh breach and equally consistent with someone with a laptop and the public archive. The claim needs a record that is not Epstein-adjacent — a live licence, a recent print timestamp, something no archive already holds. They have not offered one.
For a crew this experienced the choice is strange, and there are only two readings. Either they did not know the public files contain DAVID output, which would be a remarkable gap for a group that trades in exactly this kind of data. Or they knew, and picked the sample that would travel fastest through a newsroom rather than the one that would survive a technical review. The second reading is the one I would bet on, and it is a marketing decision rather than an evidentiary one.
This is the second driver's-licence event in nine days
Keep the calendar in view.
1 September. Brian Krebs publishes on Nexus, a service on the Russian forum Exploit selling scans of more than 153 million US and Canadian driver's licences, traced to the identity-verification firm IDScan.net, complete with the infrared and ultraviolet captures that exist to prove a licence is genuine. The FBI's New Orleans office opens an inquiry the same day. We covered it on the 5th.
3 September. By ShinyHunters' own account, exfiltration from Florida DAVID begins.
Two supplies of the same commodity, opened two days apart, from opposite ends of the system. One from a private vendor scanning licences at rental counters and dispensaries. One, allegedly, from the law-enforcement database itself, reached through the credentials of federal personnel.
The private-sector breach yields the document. The government breach yields the record behind the document — the address, the status, the driving history, the fields a forger cannot invent because they live in a state system rather than on a card. Put the two together and the gap between having someone's licence and being able to answer questions about them narrows considerably.
We said on the 5th that you cannot block a leaked licence, that there is no indicator to publish and no reissue path at this scale. Nothing about this week improves that. It is the same problem arriving from a second direction.
The seam, which is where this always lives
The access path, if the claim holds, ran through accounts belonging to FBI personnel with Florida portal credentials. Not through a flaw in DAVID's design. Through legitimate accounts of people whose employer is not the agency that owns the system.
That is the shape we keep naming: the control held, and the handoff around it belonged to nobody in particular. Florida operates DAVID and provisions access. The federal agency employs the people holding some of that access. The password-reset flaw sat between the two, and a reset flow is precisely the function that gets the least security review anywhere, because it is owned by support rather than by security.
Anyone running a portal with external-agency accounts on it should spend today on the reset path rather than the login path. MFA holds. Account recovery is where a determined stranger becomes an authenticated one.
Our position, flat
We have no receipt here. We did not detect this, we hold no indicators for it, and our first timestamp on the DAVID intrusion is this post. The claim is ShinyHunters' and the reporting is BleepingComputer's and Cybernews'.
What we contributed is one check nobody else was placed to run: whether the proof stands up. Four hundred thousand DOJ documents on one side, a threat-intel corpus on the other, one query across both. Twenty-two DAVID pages, one of them Maxwell's, timestamped to the second and public for years.
The deadline is 11 September. If a leak lands and it contains live records with 2026 print timestamps and names nobody has ever connected to Palm Beach, the claim is real and this post ages into a footnote. If what arrives is more Epstein-adjacent material, everyone reporting the 200,000 figure this week will want to revisit it.
Two days.
Was this useful? Rate this post — the widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=shinyhunters-proved-a-florida-police-dmv-breach-with-an-epstein-record-twenty-two-david-printouts-h




Comments