Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: florida-dmv (1 article)Clear

ShinyHunters claims theft of Florida driver records through a password-reset flaw

The extortion group ShinyHunters claims it breached Florida's DAVID system, an internal driver and vehicle database used by law enforcement and state officials, and stole more than 200,000 records. According to the group, a password-reset flaw let it take over several internal accounts, including those of motor-vehicle employees and, notably, an FBI agent, which it then used to pull driver files, photos, and signatures by cycling through record IDs. It posted a sample it says is a public figure's license as proof and set a leak deadline. Florida's agency has not confirmed the breach, and the claim is unverified, but the group is reportedly probing other states' motor-vehicle systems the same way.

Check
Organizations with self-service password-reset flows should test them for account-takeover flaws, and agencies operating sensitive lookup systems should monitor for accounts enumerating records by ID and for logins from unexpected sources.
Affected
Government and law-enforcement lookup systems reachable with staff accounts; a password-reset weakness let attackers hijack employee and agent logins and mass-download driver records, exposing highly sensitive identity and vehicle data for extortion.
Fix
Harden password-reset and authentication flows, require phishing-resistant authentication for privileged lookup systems, alert on bulk record access and ID enumeration, limit how much any single account can pull, and verify breach claims.