{"id":9367,"date":"2026-09-09T11:25:52","date_gmt":"2026-09-09T11:25:52","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9367"},"modified":"2026-09-09T11:25:52","modified_gmt":"2026-09-09T11:25:52","slug":"shinyhunters-claims-florida-dmv-breach-puts-data-on-the-clock","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9367","title":{"rendered":"ShinyHunters claims Florida DMV breach, puts data on the clock"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">ShinyHunters is claiming to have broken into a Florida government database containing sensitive information on the state\u2019s drivers.<\/p>\n<p class=\"wp-block-paragraph\">The notorious extortion group <a href=\"https:\/\/www.ransomware.live\/id\/U3RhdGUgb2YgRmxvcmlkYSBETVZAc2hpbnlodW50ZXJz\" target=\"_blank\" rel=\"noopener\">said<\/a> it has breached the Florida Department of Highway Safety and Motor Vehicles\u2019 Driver and Vehicle Information Database (DAVID) and claims to have stolen more than 200,000 records.<\/p>\n<p class=\"wp-block-paragraph\">As evidence, the attackers published a screenshot of a record belonging to Jeffrey Epstein that showed sensitive information, including an address, Social Security number, date of birth, driver\u2019s license number, and registered vehicles.<\/p>\n<p class=\"wp-block-paragraph\">The alleged breach comes just days after an <a href=\"https:\/\/krebsonsecurity.com\/2026\/09\/fbi-probes-service-selling-153m-drivers-licenses\/\" target=\"_blank\" rel=\"noopener\">investigation<\/a> uncovered a separate underground service offering more than 153 million digital scans of US and Canadian drivers\u2019 licenses. That database, dubbed Nexus, was apparently populated with identity documents collected through an identity-verification provider, prompting an FBI investigation into the source of the scans.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>ShinyHunters puts a deadline on the DMV<\/h2>\n<p class=\"wp-block-paragraph\">According to the group\u2019s leak-site <a href=\"https:\/\/x.com\/CyberIL\/status\/2097371659023814890\" target=\"_blank\" rel=\"noopener\">posting<\/a>, the Florida DMV was given a deadline of September 11 to negotiate before the stolen information is released.<\/p>\n<p class=\"wp-block-paragraph\">The group has reportedly claimed that it obtained access to DAVID through a password-reset weakness and subsequently compromised multiple accounts, including accounts it claimed belonged to DMV employees. It then allegedly queried driver records by ID and downloaded pages and images.<\/p>\n<p class=\"wp-block-paragraph\">DAVID provides authorized users with access to extensive driver and vehicle information, meaning a successful intrusion can yield considerably more than a database full of names and license numbers.<\/p>\n<p class=\"wp-block-paragraph\">\u201cA complete scan gives criminals much more than an identification number \u2013 it can reveal a person\u2019s photograph, signature, address, date of birth and other information contained in a legitimate government credential,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/dannyjenkinscyber\/\" target=\"_blank\" rel=\"noopener\">Danny Jenkins<\/a>, CEO of ThreatLocker, about the potential identity theft. \u201cCriminals could potentially use this data to open fraudulent accounts, conduct targeted phishing and password-reset attacks, commit insurance, medical, tax or government-benefit fraud, or create convincing synthetic identities.\u201d<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Two different sources of license data<\/h2>\n<p class=\"wp-block-paragraph\">The Florida incident and the Nexus case involve different sources of driver\u2019s license data. ShinyHunters claims to have accessed a restricted Florida government database used by law enforcement and other authorized users to look up driver and vehicle records.<\/p>\n<p class=\"wp-block-paragraph\">The Nexus database, by comparison, contained scans of government-issued IDs collected by <a href=\"http:\/\/idscan.net\/\" target=\"_blank\" rel=\"noopener\">IDScan<\/a>\u2019s identity-verification technology. The breach exposed millions of scanned IDs and led to an FBI investigation and multiple <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/multiple-class-action-lawsuits\/\" target=\"_blank\" rel=\"noopener\">lawsuits<\/a>. IDScan.net has formally confirmed its breach, while the Florida DMV has not publicly confirmed the ShinyHunters claim yet.<\/p>\n<p class=\"wp-block-paragraph\">However, the incident fits <a href=\"https:\/\/www.csoonline.com\/article\/4042191\/shinyhunters-strike-again-workday-breach-tied-to-salesforce-targeted-social-engineering-wave.html\">ShinyHunters\u2019<\/a> usual pay-or-leak playbook. In the past, the group has compromised organizations, demonstrated access with samples, and then used a publication deadline to put pressure on the victims. One such operation involved the 2024 <a href=\"https:\/\/www.csoonline.com\/article\/2140487\/snowflake-no-breach-just-compromised-credentials-say-researchers.html\">Snowflake<\/a> customer-data campaign, which hit organizations including Ticketmaster, AT&amp;T, and Santander Bank.<\/p>\n<p class=\"wp-block-paragraph\">With no public confirmation yet beyond ShinyHunters\u2019 dark web claim and its account of how it allegedly carried out the breach, it remains to be seen how the group\u2019s September 11 deadline will play out.<\/p>\n<p class=\"wp-block-paragraph\">However, if the claims prove to be true, the exposed information could pose significant identity-theft risks. Jenkins spelled out the most troubling part. Much of the information contained on a driver\u2019s license cannot simply be replaced.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe greatest concern is the permanence of this information,\u201d he said. \u201cConsumers can replace a credit card or password, but they cannot easily replace their face, birth date, signature, or identity history.\u201d <\/p>\n<p class=\"wp-block-paragraph\">Jenkins recommended freezing credit, monitoring accounts, and using stronger authentication to reduce risks from the breach.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>ShinyHunters is claiming to have broken into a Florida government database containing sensitive information on the state\u2019s drivers. The notorious extortion group said it has breached the Florida Department of Highway Safety and Motor Vehicles\u2019 Driver and Vehicle Information Database (DAVID) and claims to have stolen more than 200,000 records. As evidence, the attackers published [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9368,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9367","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9367"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9367"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9367\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9368"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}