
Florida DMV Data Breach: ShinyHunters Claims 200,000 Records
.webp)
The extortion group ShinyHunters has claimed responsibility for a data breach at the Florida DMV, alleging it pulled more than 200,000 driver records out of a restricted state database. The group published a screenshot of Jeffrey Epstein's motor vehicle record as proof and gave state officials until September 11 to make contact.
Florida's Department of Highway Safety and Motor Vehicles has not publicly acknowledged any intrusion. That silence leaves the scale of the Florida DMV data breach resting on claims made by the attackers, who have an obvious interest in sounding credible.
What the Attackers Claim They Took
ShinyHunters added a listing titled "State of Florida DMV" to its dark web leak site on September 7, and that posting made the alleged data breach public. The page carries a final warning and a download presented as evidence. The group says the theft began on September 3 and produced more than 200,000 records before it lost access.
The proof sample centres on a single record belonging to Jeffrey Epstein. Visible fields include a home address, Social Security number, date of birth, and driver's license number. Further tabs cover license transactions, prior addresses, insurance details, previous vehicles, and parking permits.
A name paired with a Social Security number and license number gives a fraudster almost everything needed to open accounts under someone else's identity. Driver photographs and signatures raise the stakes further, because both support document forgery.
How the Attackers Say They Got In
ShinyHunters describes a password-reset flaw as the entry point. The weakness let the group take over several accounts, which it says belonged to DMV staff and an FBI agent. Those accounts already held legitimate access, so the group needed no further exploitation.
From there, the method was mundane. The group stepped through record identifiers one by one, then saved the resulting pages and driver images. No malware, no zero-day, and no network intrusion appear anywhere in that account of events.
That detail points at a deeper authorisation problem. A restricted law enforcement platform should flag any account pulling tens of thousands of unrelated records in days. Rate limiting, query volume alerts, and per-user lookup auditing all exist for this scenario, but none of them interrupted the activity.
Why DAVID Holds More Than a License Photo
DAVID stands for Driver and Vehicle Information Database. Florida's motor vehicle agency runs it as a lookup tool for police officers, prosecutors, and other criminal justice officials. The agency also describes the platform as its primary reporting mechanism for fatalities and serious bodily injury.
Systems built for law enforcement carry deeper records than a public licence renewal portal. DAVID can surface application documents, photographs, signatures, address history, vehicle history, and insurance records in one view. Thousands of authorised users across the state reach that material daily.
Broad internal access is the point of a system like DAVID, and it is also the risk. Once an attacker holds a valid account, the platform behaves exactly as designed.
Florida Has Not Confirmed Anything Yet
The state agency has issued no statement acknowledging a compromise, and federal authorities have stayed quiet. Nothing about the Florida DMV data breach has been verified outside the group's own account, and no independent review of the sample exists.
The short countdown works against a careful response. A state agency needs time to verify an intrusion, scope what data left its systems, and coordinate with federal investigators. Attackers set these deadlines precisely because that work cannot finish inside the window.
Deadlines also function as theatre. Extortion groups regularly extend them, negotiate quietly past them, or publish nothing at all.
The Florida DMV Data Breach May Be the First of Several
ShinyHunters says it expects to announce more DMV breaches over the coming weeks. Separate accounts describe social engineering attacks aimed at motor vehicle platforms in other states, so the Florida DMV data breach may have opened a wider campaign.
The shift in targeting is notable. Over the past two years, the group concentrated on corporate cloud environments, hitting Salesforce customers, Snowflake tenants, and single sign-on accounts at Okta, Microsoft, and Google. State government databases sit in a different category, with different data and different legal consequences.
Recent listings show the same appetite for scale. The group claimed 284 million records from McKesson this month, ran a long campaign against misconfigured Salesforce sites, and forced an agreement out of education platform Instructure.
The Legal Exposure Runs Deep
Driver records carry their own federal protection in the United States. The Driver's Privacy Protection Act restricts how state agencies disclose personal information and allows liquidated damages of $2,500 per affected person. Applied to 200,000 records, that arithmetic turns serious fast.
Plaintiff firms move quickly on incidents involving licence data. If Florida confirms the Florida DMV data breach at anything near the alleged scale, litigation will follow its notification duties. The claimed compromise of an FBI account adds a federal dimension.
What Florida Drivers Should Do Now
Nobody outside the agency can confirm who appears in the stolen set, so caution is the sensible default for Florida licence holders. A credit freeze with the three major bureaus blocks new accounts opened in your name and costs nothing.
Records exposed in the Florida DMV data breach do not expire the way a password does. Social Security numbers appear in the sample, so an IRS Identity Protection PIN is worth requesting before tax season. Drivers should also treat any message citing real vehicle or licence details as suspect.
Florida's next move will shape how this plays out. A confirmation would trigger notification requirements, federal privacy exposure, and hard questions about bulk record extraction from a handful of compromised accounts. Continued silence past the deadline leaves drivers guessing while the attackers keep control of the story.
Subscribe to receive the latest blog posts to your inbox every week.