Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 5 sources · 3 days · First seen · Last updated
Florida driver database security breach
Overview
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a security breach of its Driver and Vehicle Information Database (DAVID). The agency reported that the incident was discovered on September 4 and has since been contained.
There are conflicting accounts regarding the cause of the breach. The FLHSMV attributed the unauthorized access to credentials from a single police officer that were improperly stored on a private device. Conversely, the hacking group ShinyHunters claimed responsibility, alleging they exploited a vulnerability in the password reset process to compromise multiple accounts, including those of government employees and an FBI agent.
As the investigation progressed, ShinyHunters claimed to have acquired over 200,000 driver records. The group attempted to substantiate this claim by posting a screenshot purportedly showing the driver’s license record of the late Jeffrey Epstein, including his Social Security number and vehicle data, though the authenticity of this image has not been independently verified. Following the public acknowledgment of the breach, ShinyHunters removed references to Florida from its leak site.
Entities
Florida Department of Highway Safety and Motor Vehicles · ShinyHunters · FBI · Plant City Police Department · Jeffrey Epstein
Timeline
-
about 8 hours ago
[TECHNOLOGY] 3 sourcesFlorida driver database breached by cybercriminalsCybercriminals breached Florida's driver and vehicle database using stolen police credentials, allegedly targeting over 200,000 records, including unverified data belonging to Jeffrey Epstein.
-
2 days ago
[TECHNOLOGY] 2 sourcesFlorida confirms breach of driver database DAVIDFlorida authorities confirmed a breach of the DAVID driver database. While officials cite compromised officer credentials, the hacking group ShinyHunters claims they exploited a password reset vulnerability.
Sources
blogspan.net · enterprisesecuritytech.com · it-boltwise.de · sofx.com · thedotgood.net