deniz.in

Markets

Weather

Loading weather

· via TechCrunch

ShinyHunters publishes hundreds of thousands of Florida driver records after DAVID breach

ShinyHunters dumped hundreds of thousands of Florida vehicle ownership files, including Social Security numbers and immigration papers, after breaching the DAVID database via a police officer's stolen credentials.

ShinyHunters publishes hundreds of thousands of Florida driver records after DAVID breach

What happened

The hacking group ShinyHunters has published hundreds of thousands of files taken from a Florida state database that stores vehicle and driver information, according to TechCrunch. The group loaded the material onto its leak site in mid-September 2026, saying it took this step because the organisation behind the database refused to pay a ransom or engage with its demands.

The compromised system, known as DAVID, serves as a state repository for motor vehicle and driver records. To back up its claims, the group posted a screenshot of what it described as a record belonging to the late sex offender Jeffrey Epstein, who owned property in Florida.

How the attackers got in

Florida's motor vehicle agency, FLHSMV, acknowledged the intrusion in a statement the previous week, TechCrunch reports. The intruders apparently did not need to defeat the state's own defences: they obtained the login credentials of a police officer, which had been saved on one of the officer's personal devices.

TechCrunch says it asked the agency to comment on the published files but had received no reply by the time of writing.

What the files contain

Having reviewed a copy of the stolen archive, TechCrunch reports that most of it consists of vehicle ownership certificates, numbering in the hundreds of thousands. These records pair the names and home addresses of buyers and sellers with the identification numbers of the vehicles they traded.

A smaller portion of the dump is considerably more sensitive. It contains Social Security numbers alongside other government-issued documents, including passports issued outside the United States and immigration paperwork. On the evidence TechCrunch reviewed, the archive does not appear to include driver's licenses or photographs of individuals.

Part of a wider pattern

The leak lands in a month already marked by a separate, larger incident involving driving credentials. Earlier in September, a breach at the identity verification company IDScan allowed attackers to steal more than 150 million driver's license images. Nothing in TechCrunch's reporting suggests the two events are connected, but together they point to the same underlying attraction: motor vehicle and identity records are concentrated, high-value targets.

Why it matters

Several things make this incident more than a routine data dump.

First, the data itself. Vehicle ownership records combining names, addresses and vehicle identification numbers are useful raw material for targeted phishing and fraud, and the smaller set of files holding Social Security numbers, foreign passports and immigration documents is directly usable for identity theft. People whose immigration paperwork sits in that subset face risks that extend well beyond financial fraud.

Second, the entry point. The breach began with credentials stored on a police officer's personal device, not with a flaw in the state's infrastructure. An agency can harden its own systems and still be compromised through the endpoints and accounts of the partners who access them, which makes device-level security and credential handling a shared responsibility rather than an internal one.

Third, the ransom dynamic. ShinyHunters stated plainly that the data went public because the victim would not pay. Declining ransom demands is a defensible policy position, but this case shows that the cost of that stance falls on the individuals whose records are exposed, not on the institutions that held them.

Finally, the timing. Arriving in the same month as the IDScan breach, the Florida leak suggests that databases of driver and vehicle information, whether held by governments or by private verification firms, are now a standing target. For anyone whose details were swept up, the practical response is limited but real: monitor credit and government benefit accounts, treat unexpected communications about vehicles or licenses with suspicion, and assume the exposed details will circulate for years.

  • #data-breach
  • #ransomware
  • #privacy
  • #security
  • #florida

Related posts