< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 5 sources · 3 days · First seen · Last updated

Florida driver database security breach

Overview

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a security breach of its Driver and Vehicle Information Database (DAVID). The agency reported that the incident was discovered on September 4 and has since been contained.

There are conflicting accounts regarding the cause of the breach. The FLHSMV attributed the unauthorized access to credentials from a single police officer that were improperly stored on a private device. Conversely, the hacking group ShinyHunters claimed responsibility, alleging they exploited a vulnerability in the password reset process to compromise multiple accounts, including those of government employees and an FBI agent.

As the investigation progressed, ShinyHunters claimed to have acquired over 200,000 driver records. The group attempted to substantiate this claim by posting a screenshot purportedly showing the driver’s license record of the late Jeffrey Epstein, including his Social Security number and vehicle data, though the authenticity of this image has not been independently verified. Following the public acknowledgment of the breach, ShinyHunters removed references to Florida from its leak site.

Entities

Florida Department of Highway Safety and Motor Vehicles · ShinyHunters · FBI · Plant City Police Department · Jeffrey Epstein

Timeline

  1. about 8 hours ago

    [TECHNOLOGY] 3 sources
    Florida driver database breached by cybercriminals

    Cybercriminals breached Florida's driver and vehicle database using stolen police credentials, allegedly targeting over 200,000 records, including unverified data belonging to Jeffrey Epstein.

  2. 2 days ago

    [TECHNOLOGY] 2 sources
    Florida confirms breach of driver database DAVID

    Florida authorities confirmed a breach of the DAVID driver database. While officials cite compromised officer credentials, the hacking group ShinyHunters claims they exploited a password reset vulnerability.

Sources

blogspan.net · enterprisesecuritytech.com · it-boltwise.de · sofx.com · thedotgood.net