Static

Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

First reported by TechCrunch ·

The signal ●○○○ Compiled by AI from TechCrunch, the single source so far
Why you might care

Your personal information, including your name, address, and vehicle details, may be publicly available if you are a Florida driver.

What happened

Hackers have published thousands of Florida drivers' data after breaching the state's motor vehicle database, known as DAVID. The group, ShinyHunters, claimed responsibility and stated the data was released because their ransom demands were not met. The breach occurred in September, and as proof, the hackers posted a screenshot of a record associated with Jeffrey Epstein. The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed the breach, explaining that hackers obtained credentials from a police officer's personal device. The stolen data includes hundreds of thousands of vehicle ownership certificates with names, addresses, and VINs. A subset of the data also contains Social Security numbers and other government-issued documents like non-U.S. passports and immigration papers, though driver's licenses and photos were not reported as compromised. This incident follows a massive data breach at identity verification company IDScan, where over 150 million driver's license images were stolen.

What it means

The increasing frequency and sophistication of attacks on government databases, particularly those containing sensitive personal information, highlight systemic vulnerabilities in public sector cybersecurity. The use of compromised credentials, a common tactic, underscores the need for robust access control and employee training on device security. This event, occurring concurrently with a large-scale breach at a private identity verification firm, suggests a broader trend of attackers targeting centralized repositories of personally identifiable information, regardless of whether they are public or private entities.

The publication of driver and vehicle data, including VINs and potentially Social Security numbers, poses significant risks for identity theft and fraud for affected individuals. The attackers' motivation, as stated, being the refusal to pay ransom, indicates a shift towards data exposure as a primary leverage tactic, moving beyond encryption-based extortion. This escalates the consequences for individuals whose data is compromised, as the information becomes permanently available and exploitable on the dark web, even if the originating breach is secured.

AI-written summary. May contain errors.