Zero Day Room
Live
Incidents

Florida DMV breach linked to stolen police

The Florida Department of Highway Safety and Motor Vehicles confirmed a data breach after credentials were stolen from a Plant City police officer's

The Florida Department of Highway Safety and Motor Vehicles confirmed a data breach after credentials were stolen from a...

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach on Thursday, attributing it to credentials stolen from a police officer's personal device. The ShinyHunters cybercriminal organization claimed responsibility for the attack earlier in the week.

Officials said they first learned of the incident on September 4. The department stated that a criminal actor exploited a single Plant City Police Department user's credentials, which were improperly stored on the employee's personal electronic device. Plant City is a suburb of Tampa.

ShinyHunters' claim and proof

ShinyHunters publicly claimed access to FLHSMV data on Monday. As proof, the group shared alleged photos of a DMV record connected to the late financier and convicted sex offender Jeffery Epstein. The Florida department did not respond to requests for comment for several days before confirming the breach's legitimacy on Thursday night.

FLHSMV has notified other state government offices and is working with the Florida Digital Service on the investigation. The department initially blamed an unnamed international cybercriminal organization.

Group's recent attack history

ShinyHunters is a prolific cybercriminal group with a history of high-profile attacks. The group recently claimed credit for breaches at bank IT provider Jack Henry and healthcare technology company McKesson. McKesson told regulators that data from its oncology and surgical business units was stolen.

In May, the group caused widespread disruption with an attack on a popular educational software suite. That followed an April attack on the world's largest medical device company, which resulted in the theft of information belonging to more than four million people. Other past victims include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar.

When the Florida breach claims first emerged, some cybersecurity experts speculated it might be connected to the recently confirmed leak of 153 million driver's licenses from identity verification firm IDScan. ShinyHunters had previously expressed interest in purchasing the ID database from the hackers behind the IDScan breach.

Use of AI in attacks

A new report from artificial intelligence company Anthropic, released Thursday, details how suspected ShinyHunters affiliates are using AI tools. The report states these actors use AI to scan for credentials, map unfamiliar systems, and steal data for extortion. Anthropic said that in one case, an operator progressed from a stolen developer token to full administrative access of a victim's cloud environment in roughly three hours.

Incident responders at Google confirmed last week that members of ShinyHunters are employing AI tools from Anthropic at various stages of their attacks. The integration of AI appears to be accelerating the group's capability to compromise systems and escalate access.

Related coverage

More from Incidents