ShinyHunters claims Florida DMV breach, puts data on the clock
The ransomware group claims it breached the state’s DAVID database and has threatened to publish the allegedly stolen records after a September 11 deadline.
ShinyHunters is claiming to have broken into a Florida government database containing sensitive information on the state’s drivers.
The notorious extortion group said it has breached the Florida Department of Highway Safety and Motor Vehicles’ Driver and Vehicle Information Database (DAVID) and claims to have stolen more than 200,000 records.
As evidence, the attackers published a screenshot of a record belonging to Jeffrey Epstein that showed sensitive information, including an address, Social Security number, date of birth, driver’s license number, and registered vehicles.
The alleged breach comes just days after an investigation uncovered a separate underground service offering more than 153 million digital scans of US and Canadian drivers’ licenses. That database, dubbed Nexus, was apparently populated with identity documents collected through an identity-verification provider, prompting an FBI investigation into the source of the scans.
ShinyHunters puts a deadline on the DMV
According to the group’s leak-site posting, the Florida DMV was given a deadline of September 11 to negotiate before the stolen information is released.
The group has reportedly claimed that it obtained access to DAVID through a password-reset weakness and subsequently compromised multiple accounts, including accounts it claimed belonged to DMV employees. It then allegedly queried driver records by ID and downloaded pages and images.
DAVID provides authorized users with access to extensive driver and vehicle information, meaning a successful intrusion can yield considerably more than a database full of names and license numbers.
“A complete scan gives criminals much more than an identification number – it can reveal a person’s photograph, signature, address, date of birth and other information contained in a legitimate government credential,” said Danny Jenkins, CEO of ThreatLocker, about the potential identity theft. “Criminals could potentially use this data to open fraudulent accounts, conduct targeted phishing and password-reset attacks, commit insurance, medical, tax or government-benefit fraud, or create convincing synthetic identities.”
Two different sources of license data
The Florida incident and the Nexus case involve different sources of driver’s license data. ShinyHunters claims to have accessed a restricted Florida government database used by law enforcement and other authorized users to look up driver and vehicle records.
The Nexus database, by comparison, contained scans of government-issued IDs collected by IDScan’s identity-verification technology. The breach exposed millions of scanned IDs and led to an FBI investigation and multiple lawsuits. IDScan.net has formally confirmed its breach, while the Florida DMV has not publicly confirmed the ShinyHunters claim yet.
However, the incident fits ShinyHunters’ usual pay-or-leak playbook. In the past, the group has compromised organizations, demonstrated access with samples, and then used a publication deadline to put pressure on the victims. One such operation involved the 2024 Snowflake customer-data campaign, which hit organizations including Ticketmaster, AT&T, and Santander Bank.
With no public confirmation yet beyond ShinyHunters’ dark web claim and its account of how it allegedly carried out the breach, it remains to be seen how the group’s September 11 deadline will play out.
However, if the claims prove to be true, the exposed information could pose significant identity-theft risks. Jenkins spelled out the most troubling part. Much of the information contained on a driver’s license cannot simply be replaced.
“The greatest concern is the permanence of this information,” he said. “Consumers can replace a credit card or password, but they cannot easily replace their face, birth date, signature, or identity history.”
Jenkins recommended freezing credit, monitoring accounts, and using stronger authentication to reduce risks from the breach.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.