Was Florida’s DMV Really Hacked? What ShinyHunters’ Jeffrey Epstein Screenshot Actually Proves

ShinyHunters says it breached Florida’s DAVID driver database and stole more than 200,000 records, using a Jeffrey Epstein record as proof. A sherafy.com provenance audit finds the screenshot is consistent with genuine DAVID data—but much of what it shows was documented years earlier, leaving the timing, access method and alleged scale unproven.
A desk scene shows a Florida driver’s license, a computer screen displaying a DMV-style record, and investigative notes and evidence materials.
Contents

ShinyHunters has not publicly proved that it breached Florida’s driver database in September 2026 or stole more than 200,000 records. The group has produced a screenshot that closely resembles a genuine record from Florida’s Driver and Vehicle Information Database, or DAVID, but that establishes far less than the word “breach” suggests.

A sherafy.com review found that a genuine Florida DAVID record for Jeffrey Epstein was already generated in March 2005. It contains the same expired-license period and substantial vehicle information that make the new screenshot appear convincing. Later government records separately document Epstein’s sex-offender status and other identifying information. And independent National Transportation Safety Board records show that the newer-looking DAVID “Record Detail” interface visible in the alleged sample existed years before September 2026.

That does not mean ShinyHunters fabricated the screenshot. In fact, its structure is strongly consistent with genuine DAVID output, and at least one element—the exact signature image visible in published versions—has not been traced by sherafy.com to an earlier public source.

The evidence therefore supports a narrower conclusion:

The Epstein screenshot is credible evidence that the image may derive from genuine DAVID data, but it does not establish when the record was accessed, how it was obtained, whether access was unauthorized, or whether ShinyHunters actually exfiltrated more than 200,000 Florida records.

As of September 9, 2026, Florida authorities had not publicly confirmed the alleged breach.

What ShinyHunters actually claims happened

On September 7, ShinyHunters listed “State of Florida DMV” on its extortion site and threatened to release allegedly stolen data if Florida did not engage with the group.

The formal agency is the Florida Department of Highway Safety and Motor Vehicles (FLHSMV). DAVID is the restricted Driver and Vehicle Information Database used by law-enforcement and other authorized government users.

BleepingComputer, which communicated directly with ShinyHunters, reported that the group claims it:

  • began accessing DAVID on September 3;
  • exploited a password-reset weakness;
  • compromised multiple accounts, allegedly including FLHSMV employees and an FBI account;
  • iterated through DAVID records by identifier;
  • downloaded HTML pages and associated images;
  • obtained more than 200,000 records;
  • subsequently lost access while the alleged password-reset weakness was being fixed.

Those details are important, but their provenance is equally important: they come from the alleged attacker.

BleepingComputer reported the claims as claims and said it contacted FLHSMV and the FBI for confirmation.

Cybernews independently reported seeing the Epstein sample and confirmed that it showed a photograph, signature, expired driver record and other information. It likewise reported that the Florida agency had not confirmed a breach.

That gives us two different categories of evidence.

Claim Current status
ShinyHunters publicly claimed a Florida DAVID breach Verified
ShinyHunters supplied an Epstein screenshot as proof Verified
Screenshot resembles genuine DAVID output Strongly supported
Unauthorized DAVID access occurred in September 2026 Not independently established
A password-reset vulnerability was exploited Attacker allegation
FLHSMV and FBI accounts were compromised Attacker allegation
More than 200,000 records were stolen Attacker allegation
FLHSMV’s internal network was penetrated Not established

That distinction is central to understanding the story.

The Epstein screenshot looks like a real DAVID record

The sample is not obviously bogus.

Independent government records provide unusually useful comparison material.

In a 2018 federal highway-safety investigation, the NTSB obtained and published a Florida DAVID record. Its interface carries the same DAVID — Driver and Vehicle Information Database branding and a “Record Detail” page containing fields for customer name, driver-license status, license identification, address, birth date, height, license dates and other driver information.

Another NTSB investigation contains a DAVID record printed on January 15, 2024. It uses the same basic “Record Detail” interface and shows how DAVID continued presenting current and historical driver information years later.

Those records matter because they are unrelated to Epstein or ShinyHunters. They independently establish what genuine DAVID output looked like.

The alleged ShinyHunters screenshot is therefore structurally consistent with authentic DAVID.

But interface similarity answers only one question:

Could this be a DAVID record?

It does not answer:

When was it retrieved?

A screen design demonstrably in use years before September 2026 cannot itself authenticate a September 2026 intrusion.

A real Jeffrey Epstein DAVID record dates back to March 2005

The most important provenance problem with ShinyHunters’ sample is that Epstein’s Florida DAVID history is not newly revealed information.

A DOJ-released FBI investigative file contains a Florida D.A.V.I.D. Individual Summary Page for Jeffrey E. Epstein printed on March 15, 2005.

The historical page identifies his Florida license as expired and gives an issue date of January 3, 1996 and expiration date of January 20, 2002. It contains Epstein’s Palm Beach address, physical characteristics, conditional messages including “MOTORCYCLE ALSO” and “SAFE DRIVER,” and a long table of vehicles associated with the record.

That vehicle history includes multiple Mercedes-Benz vehicles along with Chevrolet, Harley-Davidson, Volkswagen, Jeep and other records.

These are not details first exposed by ShinyHunters in 2026.

They existed in an actual DAVID printout generated more than 21 years earlier and subsequently released as part of the federal Epstein document corpus.

But the alleged ShinyHunters screenshot is not simply the 2005 page

This distinction is just as important.

The 2005 DAVID page explicitly states:

“No Image Available”

and

“No Signature on File.”

The screenshot circulated by ShinyHunters reportedly contains both a photograph and signature and uses a later DAVID interface.

So the evidence does not support the claim that ShinyHunters merely took the old 2005 screenshot and reposted it.

Something changed between those records.

The appropriate question is therefore not whether the screenshots are identical. They clearly are not.

The better question is:

How much of the information in ShinyHunters’ supposedly new proof was already independently obtainable before the alleged breach?

How much of ShinyHunters’ Epstein “proof” was already known?

The answer is: a substantial amount.

Element shown or reportedly shown Evidence predating September 2026 Value as proof of a new breach
Epstein’s identity and basic physical information Numerous government and court records Very low
Expired Florida license 2005 DAVID record Very low
January 1996 issue date 2005 DAVID record Very low
January 2002 expiration 2005 DAVID record Very low
Palm Beach address 2005 DAVID and other records Very low
“SAFE DRIVER” notation 2005 DAVID record Very low
Motorcycle notation 2005 DAVID record Very low
Historical vehicle information 2005 DAVID and later Florida records Low
Sex-offender status Established years earlier in Florida records Low
DAVID “Record Detail” interface Independently documented by at least 2018 Low for dating the access
Exact signature image shown Not traced by sherafy.com to an earlier public DAVID copy Potentially meaningful
A field demonstrably updated after all previously available records None publicly established so far Would be highly meaningful

This is why Epstein is an unusually difficult person to use as independent proof of a fresh database breach.

That does not mean choosing him was suspicious.

For an extortion group, Epstein is an obvious publicity sample: his name guarantees attention, the record is instantly recognizable, and publishing information about a deceased notorious offender raises different privacy concerns than exposing an uninvolved living Florida resident.

But those same characteristics make his record unusually weak for establishing provenance.

Why does an expired 2002 license show a later “Sexual Offender” flag?

One feature of the screenshot can initially look contradictory.

Epstein’s Florida license expired in 2002. His Florida sex-offender status came years afterward. How could both appear on the same DAVID screen?

Florida’s own documentation provides the answer.

The Florida Department of Law Enforcement’s guidelines state that once the agency verifies a sex-offender registration requirement, it flags that person’s record in DAVID.

Separate DOJ material confirms that Epstein registered as a Florida sexual offender after his release from custody in July 2009.

DAVID therefore need not be a frozen snapshot of what Epstein’s physical license looked like in 2002.

It can combine an old license record with information later associated with the person.

That makes the combination of:

expired 2002 license + later sexual-offender flag

internally plausible.

In fact, it supports the interpretation that the screenshot represents a later state of the DAVID record than the March 2005 printout.

What it still does not establish is how much later.

A record updated after 2009 is not necessarily a record queried in September 2026.

The DAVID interface cannot establish when the screenshot was taken

This is one of the most important limitations in the evidence.

The ShinyHunters screenshot reportedly uses the newer DAVID “Record Detail” interface rather than the much older “Individual Summary Page” format seen in Epstein’s 2005 record.

That might look like evidence of a recent query.

It is not.

The NTSB publicly released a Florida DAVID “Record Detail” page generated on May 9, 2018. Another federal investigation contains a substantially similar DAVID interface generated on January 15, 2024.

So the visual design establishes, at most, that the screenshot comes from the newer era of DAVID.

It cannot distinguish among a query made in:

  • 2018;
  • 2020;
  • 2024;
  • 2025;
  • September 2026.

Without trustworthy timestamp information or independent access logs, the interface cannot date the alleged breach.

Could someone have reconstructed the Epstein screenshot using public information?

Much of it, yes.

By September 2026, publicly available material provided enough information to reconstruct a surprisingly convincing Epstein driver profile:

  • genuine historical DAVID information;
  • his expired license dates;
  • former addresses;
  • extensive vehicle records;
  • sex-offender status;
  • photographs;
  • examples of later DAVID screen designs.

The Justice Department’s Epstein Library alone contains a large collection of released investigative and court material, and DOJ warns that its enormous disclosure corpus may even include personally identifiable information that was inadvertently left unredacted. The library was last updated July 17, 2026—before the alleged September intrusion.

That means many apparently sensitive details in the ShinyHunters sample have little value for proving recency.

But reconstructibility is not proof of fabrication.

There is currently no affirmative evidence that ShinyHunters manually created a fake DAVID screen.

The correct conclusion is narrower:

Because much of the screenshot can be independently accounted for using information that existed before September 2026, the sample carries much less evidentiary weight than a record containing clearly recent, previously unavailable data would carry.

So is the ShinyHunters screenshot fake?

There is not enough evidence to say that.

The screenshot appears consistent with genuine DAVID output.

A reasonable inference from its structure is that it may originate from an authentic DAVID view—or at minimum was produced by someone familiar with how DAVID records look.

One unresolved detail is especially important: the signature image.

Epstein’s March 2005 DAVID record expressly said no signature was on file, while later DAVID records demonstrate that the system can display stored signature information.

sherafy.com was unable to establish that the exact signature visible in the reported ShinyHunters sample had already appeared in a publicly available DAVID record.

That makes the signature potentially more useful evidence of DAVID provenance than the license dates, vehicle information or sex-offender label.

It still cannot independently prove September 2026 access.

An authentic database element can establish where information originated without establishing when the person now possessing it acquired it.

ShinyHunters’ track record makes the allegation plausible—not proven

The identity of the claimant matters, but only so far.

The FBI describes ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion.

This is therefore not equivalent to an anonymous social-media account claiming to have hacked Florida.

ShinyHunters and actors using that name have previously been associated with genuine compromises and stolen data.

That increases the prior plausibility of the Florida allegation.

But the FBI’s same May 2026 advisory contains an unusually relevant warning: threat actors can use real or exaggerated claims of access to pressure victims into paying. The FBI also notes that some supposed compromising material claimed by extortionists may not exist at all.

A separate 2026 ShinyHunters incident illustrates why independent verification matters. After the group claimed extensive data theft from the National Association of Insurance Commissioners, NAIC acknowledged unauthorized access but disputed parts of the group’s characterization, saying some stolen material was already public or consisted of outdated information. BleepingComputer also reported that the attackers acknowledged an earlier inventory had been exaggerated after relying on AI-generated analysis.

None of that proves the Florida claim is exaggerated.

It demonstrates why an extortionist’s record count should not become a confirmed statistic merely because the group has successfully stolen data before.

What about the claimed DAVID password-reset vulnerability?

ShinyHunters told BleepingComputer it obtained access through a password-reset weakness that allowed the attackers to compromise legitimate DAVID accounts.

There is one independently verifiable piece of that story:

DAVID does have password-recovery functionality.

The current DAVID sign-in page includes a “Forgot your password?” option.

That makes an account-recovery attack technically conceivable.

It does not prove that a vulnerability existed.

As of September 9, sherafy.com found no public:

  • FLHSMV vulnerability advisory;
  • technical incident report;
  • CVE tied to this claim;
  • independent security-research confirmation;
  • official statement confirming that DAVID’s password-reset function had been exploited.

The existence of a password-reset button cannot be used as corroboration that the button was vulnerable.

For now, the password-reset exploit remains an attacker allegation.

Was the Florida DMV itself actually “hacked”?

Possibly—but the word “hacked” obscures an important technical distinction.

DAVID is not merely a public consumer DMV website. It is a restricted driver-and-vehicle information system accessible to authorized users.

If ShinyHunters’ own account is accurate, the attackers did not necessarily penetrate FLHSMV’s central internal network or compromise a database server directly.

They say they compromised valid DAVID user accounts.

Florida documentation shows that outside law-enforcement and government organizations use DAVID and that access to records through the system is monitored and controlled. FLHSMV’s public-record policy even contains procedures dealing specifically with records showing which law-enforcement agencies accessed information through DAVID.

An attacker using hijacked authorized credentials could therefore obtain protected DMV information without breaking directly into Florida’s underlying database infrastructure.

That would still be serious.

Florida law defines a security breach as unauthorized access to electronically stored personal information, and its notification provisions also apply to governmental entities.

So there are at least three distinct claims:

  1. Someone obtained unauthorized access to DAVID.
  2. FLHSMV’s own internal systems were directly compromised.
  3. More than 200,000 records were actually extracted.

Evidence for one does not automatically prove the others.

Does one Epstein record prove 200,000 Florida records were stolen?

No.

This is probably the simplest unresolved question in the story.

ShinyHunters says it retrieved more than 200,000 records by iterating through DAVID identifiers and downloading associated pages and images.

The public evidence currently consists principally of one person’s record.

One authentic record could demonstrate access to one record.

It cannot establish a population of 200,000.

Public confirmation of the claimed scale would require additional evidence such as:

  • FLHSMV access or exfiltration logs;
  • authenticated records involving multiple unrelated people;
  • samples containing information clearly unavailable before the alleged intrusion;
  • forensic findings documenting automated enumeration;
  • an official affected-person estimate;
  • breach notifications;
  • credible independent analysis of the dataset.

Until then, “more than 200,000 records” should always be attributed to ShinyHunters, not reported as an established victim count.

Florida has tools that could help determine what happened

DAVID is not necessarily an unlogged black box.

FLHSMV’s Office of Inspector General previously conducted an engagement specifically concerning the DAVID High-Profile Individuals List, reviewing controls intended to monitor improper access to personal information associated with designated high-profile individuals.

FLHSMV’s records policy also expressly discusses records concerning who accessed information through DAVID, while noting that some access information may be withheld when connected with active investigations, undercover personnel, surveillance or other exemptions.

Those records do not tell us whether Jeffrey Epstein was on a monitored list in 2026.

They do establish that DAVID access can leave an auditable trail.

If somebody improperly queried large numbers of records through compromised accounts, investigators may therefore have substantially better evidence than the public currently does.

Why hasn’t Florida confirmed the breach?

Florida’s silence should not be mistaken for proof that nothing happened.

Under Florida Statute §501.171, a breach generally means unauthorized electronic access to personal information. For a breach affecting at least 500 Floridians, the covered entity must notify the state Department of Legal Affairs as expeditiously as practicable but generally no later than 30 days after determining that a breach occurred or that there is reason to believe one occurred.

Notices to individuals similarly allow time to determine the scope, identify affected people and restore the integrity of the affected system. Law enforcement can also request a notification delay if public notice would interfere with a criminal investigation.

Florida law separately makes significant categories of cybersecurity information confidential and exempt from public-record disclosure, including incident information, security practices, certain technical details and information about portal access that could facilitate further unauthorized activity.

So two days of official silence after a criminal group posts an extortion demand tells us relatively little.

Florida could be:

  • investigating a genuine breach;
  • investigating an attempted breach;
  • determining the scope;
  • coordinating with federal law enforcement;
  • concluding that the attackers exaggerated or fabricated their access.

The public evidence does not currently distinguish among those possibilities.

No confirmation means unconfirmed. It does not mean disproven.

Should Florida drivers assume their information was stolen?

No—not on the evidence currently available.

There is not enough public information to identify any living Florida driver whose DAVID record was actually taken as part of this alleged incident.

Florida residents should therefore be wary of two opposite mistakes:

  • dismissing the claim entirely because the state has not confirmed it; or
  • assuming that 200,000 Floridians have definitely had their full DMV records stolen because ShinyHunters says so.

People should rely on formal FLHSMV, Florida Attorney General or federal notifications if affected populations are identified.

The FBI’s existing guidance concerning ShinyHunters also recommends caution when someone claims to possess personal information: verify unusual communications through known channels, do not send payments in response to extortion, and avoid suspicious links or unexpected attachments.

A breach story itself can become useful material for phishing. An email saying “your Florida DMV record was leaked—click here to protect yourself” should not be trusted merely because the underlying news story is real.

What evidence would actually confirm the Florida DAVID breach?

The strongest confirmation would not be another dramatic screenshot.

It would be evidence that resolves time, authorization and scale.

That could include:

  • FLHSMV publicly confirming unauthorized DAVID access;
  • an FBI or other law-enforcement statement confirming the incident;
  • audit logs showing unauthorized queries during the alleged September 3–7 window;
  • evidence establishing which accounts were compromised;
  • authenticated records containing information unavailable before the alleged breach;
  • statutory breach notifications identifying affected residents;
  • forensic evidence showing automated enumeration or mass downloading;
  • a credible count of affected DAVID records.

That evidence could emerge after this article is published.

If it does, it may confirm much or all of what ShinyHunters has claimed.

But it has not emerged publicly yet.

So what does ShinyHunters’ Jeffrey Epstein screenshot actually prove?

The best-supported answer is more nuanced than either “Florida DMV was hacked” or “the screenshot is fake.”

Verified: ShinyHunters made the claim and supplied a Jeffrey Epstein record as purported evidence.

Strongly supported: The screenshot’s format is consistent with genuine Florida DAVID output.

Verified: A genuine Epstein DAVID record generated in March 2005 already contained his expired 1996–2002 license period and extensive vehicle information.

Verified: Florida’s system can later flag DAVID records with sex-offender information, explaining why a historical license record can display a status acquired years afterward.

Verified: A newer-looking DAVID “Record Detail” interface existed by at least 2018 and remained in use in 2024, meaning the screen design cannot date the alleged access to September 2026.

Reasonable inference: The screenshot may derive from a genuine later DAVID record rather than simply being a copy of the 2005 printout.

Not established: That ShinyHunters queried the record in September 2026.

Not established: That a DAVID password-reset vulnerability was exploited.

Not established: That FLHSMV or FBI user accounts were compromised.

Not established: That Florida’s internal DMV infrastructure was directly penetrated.

Not established: That more than 200,000 driver records were stolen.

The Epstein sample therefore proves less than it initially appears to, but it is not worthless.

It provides credible evidence of DAVID provenance while failing to answer the questions that actually determine whether the claimed breach happened as described.

For now, the most accurate description is:

ShinyHunters has made a plausible but unconfirmed claim of unauthorized access to Florida’s DAVID system. Its Epstein screenshot is consistent with genuine DAVID data, but it does not independently prove the date, method or claimed scale of the intrusion.

That could change quickly if Florida authorities, investigators or genuinely new records provide the missing evidence.

References and Further Reading

Primary and government sources

Reporting on the alleged September 2026 incident

Editorial currency note: This is a fast-moving cybersecurity allegation. The evidence status, affected-record count, official response and notification obligations could materially change after publication, particularly around ShinyHunters’ stated September 11, 2026 deadline. The article should be updated if FLHSMV, the FBI, the Florida Attorney General or independently authenticated new evidence resolves any of the currently unverified claims.

Cite this article

Published September 10, 2026

Think something here is wrong, incomplete, outdated, or insufficiently supported? You can challenge a factual claim, source, interpretation, missing context, or privacy issue.

Learn How the challenge process works


More to think on...