Hackers claiming to operate under the ShinyHunters name say they have breached Florida’s driver and vehicle database and stolen more than 200,000 records, including sensitive information about motorists.
The group has posted the Florida Highway Safety and Motor Vehicles (FLHSMV) on its extortion website, threatening to publish the alleged haul unless the agency enters negotiations.
As purported evidence, the attackers released an image showing the driving record of convicted sex offender Jeffrey Epstein. The screenshot appears to contain personal details including an address, date of birth, driving licence information, registered vehicles and a Social Security number.
The material was allegedly taken from DAVID, the Driver and Vehicle Information Database used by Florida officials and law enforcement to retrieve information about motorists and vehicles.
FLHSMV describes DAVID as a system that provides immediate access to driver and motor vehicle information for law enforcement and criminal justice officials. It is also used to report fatalities and serious bodily injuries.
How the alleged Florida DMV breach happened
ShinyHunters claims it exploited a weakness in the system’s password-reset process, allowing the group to take control of several accounts. The accounts allegedly included those belonging to Florida DMV employees and an FBI agent.
Once inside, the attackers say they worked through records by their identification numbers and downloaded associated web pages and images. They claim the operation began on September 3 and resulted in the theft of more than 200,000 records.
The group has since said it lost access to DAVID and that the password-reset vulnerability is being fixed. The claims have not been independently verified.
FLHSMV and the FBI were contacted about the alleged breach, but no response had been received at the time of reporting.
A source also said the group was attempting to target motor vehicle databases in other US states through social-engineering attacks. ShinyHunters has indicated that it expects to announce further alleged breaches in the coming weeks.
ShinyHunters data theft campaigns
ShinyHunters is a name associated with a number of cybercriminals involved in data theft and extortion attacks against businesses and public-facing online services.
The group has previously been linked to attacks on cloud software platforms and companies including Google, Cisco, Pornhub and Match Group. Its methods have included compromising third-party providers and using stolen authentication tokens to reach connected corporate systems.
More recently, attackers using the name have been associated with voice-phishing campaigns targeting accounts at Okta, Microsoft and Google. In such attacks, criminals impersonate technical support staff and attempt to persuade employees to surrender passwords or multi-factor authentication codes.
The group was also blamed for a major data-theft incident affecting Instructure’s Canvas platform in May. Instructure later reached an agreement with the attackers aimed at preventing stolen information from being released online.
Several arrests over the years have involved people accused of operating under the ShinyHunters name, including suspects connected with the Snowflake data thefts, the PowerSchool breaches and the Breached hacking forum. Despite those cases, groups using the label continue to conduct extortion campaigns.
