Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
First reported by TechCrunch ·
Your personal information, including your name, address, and vehicle details, may be publicly available if you are a Florida driver.
Hackers have published thousands of Florida drivers' data after breaching the state's motor vehicle database, known as DAVID. The group, ShinyHunters, claimed responsibility and stated the data was released because their ransom demands were not met. The breach occurred in September, and as proof, the hackers posted a screenshot of a record associated with Jeffrey Epstein. The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed the breach, explaining that hackers obtained credentials from a police officer's personal device. The stolen data includes hundreds of thousands of vehicle ownership certificates with names, addresses, and VINs. A subset of the data also contains Social Security numbers and other government-issued documents like non-U.S. passports and immigration papers, though driver's licenses and photos were not reported as compromised. This incident follows a massive data breach at identity verification company IDScan, where over 150 million driver's license images were stolen.
The increasing frequency and sophistication of attacks on government databases, particularly those containing sensitive personal information, highlight systemic vulnerabilities in public sector cybersecurity. The use of compromised credentials, a common tactic, underscores the need for robust access control and employee training on device security. This event, occurring concurrently with a large-scale breach at a private identity verification firm, suggests a broader trend of attackers targeting centralized repositories of personally identifiable information, regardless of whether they are public or private entities.
The publication of driver and vehicle data, including VINs and potentially Social Security numbers, poses significant risks for identity theft and fraud for affected individuals. The attackers' motivation, as stated, being the refusal to pay ransom, indicates a shift towards data exposure as a primary leverage tactic, moving beyond encryption-based extortion. This escalates the consequences for individuals whose data is compromised, as the information becomes permanently available and exploitable on the dark web, even if the originating breach is secured.
AI-written summary. May contain errors.