The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that cybercriminals managed to breach one of their systems using a police employee’s credentials, potentially exposing sensitive personal information of drivers in the state.
According to an official statement from the agency, authorities became aware of the unauthorized access on September 4 and took immediate action to contain it.
The investigation revealed that the intruders exploited credentials from a Plant City Police Department employee, which had been improperly stored on a personal electronic device.
Data Breach in Florida's Driver and Vehicle Database
The compromised system, known as DAVID, is Florida’s driver and vehicle database. This restricted-access platform is used by authorized agencies and contains information such as names, Social Security numbers, birth dates, addresses, photos, signatures, driving histories, and vehicle data.
As reported by NBC News, the notorious cybercriminal group ShinyHunters claimed responsibility for the breach. They posted on their dark web site that the Florida vehicle system was among their targets, setting a September 11 deadline to negotiate before allegedly releasing the obtained data.
Controversial Proof of Breach
To substantiate their claimed access, ShinyHunters displayed a screenshot purportedly showing the driver’s license record of the late financier and convicted sex offender Jeffrey Epstein, a former Florida resident. The image allegedly included details such as his Social Security number, driver’s license, and registered vehicles.
NBC News noted they could not independently verify the authenticity of the screenshot.
ShinyHunters claims to have acquired over 200,000 driver records, although this figure has not been confirmed by Florida authorities.
Negotiations and Unconfirmed Resolutions
Following FLHSMV's public acknowledgment of the breach, ShinyHunters removed references to Florida from their site on Friday afternoon. Ian Gray, Vice President of Intelligence at threat monitoring firm Flashpoint, explained to NBC News that such behavior might occur following communications between attackers and their victims.
“When a victim is no longer mentioned on a blog, it usually means negotiations took place,” Gray stated.
There is no public confirmation that Florida has paid any ransom or reached an agreement with the cybercriminals. FLHSMV did not respond to NBC News inquiries about ongoing negotiations with the group.
Broader Implications and Security Concerns
This incident comes on the heels of another attack involving identification information in the United States. Earlier in September, IDScan.net, a company providing identity verification and driver’s license scanning services to private businesses, reported that an unauthorized third party might have accessed or copied certain information stored in their clients’ cloud accounts.
The perpetrators of that attack claimed to have obtained 160 million identification records, a number not officially confirmed. Allegedly compromised information includes an ID belonging to Defense Secretary Pete Hegseth. The FBI has launched an investigation into the incident.
Currently, there is no public evidence linking the two attacks. Nevertheless, these cases highlight the risks associated with storing and accessing extensive databases containing personal identification information.
The unauthorized access to the DAVID system is particularly significant for Florida, home to a large Cuban community with numerous members holding driver’s licenses and registered vehicles. Authorities have not specified how many individuals were affected or which specific records were compromised.
FLHSMV has reported the breach to the Florida Attorney General’s Office and is collaborating with the Florida Digital Service and the Florida Department of Law Enforcement (FDLE) on the investigation.
As this is an ongoing criminal investigation, the agency indicated that additional information will be released when deemed appropriate.
This breach comes just days after U.S. authorities opened another investigation into an attempted cyberattack on hundreds of thousands of accounts on the social network X.
Key Questions on Florida's Data Breach Incident
What information was potentially exposed in the Florida data breach?
The breach of the DAVID system could have exposed personal information such as names, Social Security numbers, birth dates, addresses, photos, signatures, driving histories, and vehicle data.
Who claimed responsibility for the Florida driver’s license system breach?
The cybercriminal group ShinyHunters claimed responsibility for the breach, stating on the dark web that Florida’s vehicle system was among their targets.
Has Florida paid a ransom or reached an agreement with the hackers?
There is no public confirmation that Florida has paid any ransom or made an agreement with the hackers. The FLHSMV has not responded to inquiries regarding negotiations.
Are the Florida breach and the IDScan.net incident related?
Currently, there is no public evidence suggesting a connection between the Florida data breach and the IDScan.net incident. Both highlight the vulnerabilities of storing personal data in extensive databases.