Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
Officials in Florida said Thursday the state Department of Motor Vehicles suffered a data breach af 2026-9-11 20:16:53 Author: therecord.media(查看原文) 阅读量:3 收藏

Officials in Florida said Thursday the state Department of Motor Vehicles suffered a data breach after credentials were stolen from a police officer who had his login information on a personal device. 

On Monday, the ShinyHunters cybercriminal organization claimed they obtained access to data from the Florida Department of Highway Safety and Motor Vehicles (FLHSMV). 

The department did not respond to repeated requests for comment throughout the week but on Thursday night, it publicly confirmed the legitimacy of the breach. 

Officials initially learned of the breach on September 4 and blamed it on an unnamed “international cybercriminal organization.”

“The Department immediately launched an investigation, which determined that a criminal actor was able to take advantage of a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device,” the department said. 

Plant City is a small suburb outside of Tampa. FLHSMV has notified other Florida government offices and is partnering with the Florida Digital Service to investigate the breach. 

As proof of their access, the ShinyHunters group shared alleged photos of the DMV record tied to American financier and child sex offender Jeffery Epstein. 

When the claims of the breach initially emerged, some cybersecurity experts believed it was tied to the recently confirmed breach involving the 153 million driver’s licenses leaked by identity verification firm IDScan. ShinyHunters had previously asked to purchase the ID database from the hackers behind the IDScan breach. 

The group most recently took credit for attacks on bank IT provider Jack Henry as well as pharmaceutical and healthcare technology company McKesson, which told regulators data from their oncology and surgical business units was stolen. 

The group caused chaos across the U.S. in May with an attack on a widely used educational software suite and stole the information of more than four million people after attacking the world’s largest medical device company in April. 

Other victims include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill and ADT and gaming company Rockstar.

Artificial Intelligence company Anthropic released a report on Thursday that said suspected affiliates of ShinyHunters used AI to scan for credentials, map unfamiliar systems and steal data from their victims for extortion. The company said that in one case, an operator moved from a stolen developer token to full administrative access to a victim’s cloud environment in about three hours.

Incident responders at Google also confirmed last week that members of the group are using AI tools from Anthropic at various stages of its attacks. 


文章来源: https://therecord.media/florida-shiny-hunters-motor-vehicle
如有侵权请联系:admin#unsafe.sh