Florida DMV Data Breach Linked to Stolen Officer Credentials, ShinyHunters Claims Responsibility
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed a data breach stemming from a police officer's compromised credentials, improperly stored on a personal device. The notorious cybercriminal group **ShinyHunters** has claimed responsibility, showcasing evidence tied to high-profile individuals.
Officials in Florida announced a significant data breach affecting the state's Department of Motor Vehicles. The breach was traced back to credentials stolen from a police officer who had their login information on a personal electronic device.
On Monday, the cybercriminal organization **ShinyHunters** publicly claimed to have gained access to data from the **Florida Department of Highway Safety and Motor Vehicles** (**FLHSMV**).
After initially remaining silent on the claims, the department publicly acknowledged the legitimacy of the breach on Thursday evening.
### Investigation Reveals Source of Compromise
The **FLHSMV** first became aware of the breach on September 4. Their investigation determined that a "criminal actor was able to take advantage of a single **Plant City Police Department** user's credentials that were improperly housed on the employee's personal electronic device."
**Plant City** is a suburb located outside of Tampa. The **FLHSMV** has since notified other Florida government offices and is collaborating with the **Florida Digital Service** to investigate the incident further.
### ShinyHunters' Proof and Past Activities
As proof of their access, the **ShinyHunters** group allegedly shared photos of **DMV** records connected to American financier and convicted child sex offender **Jeffrey Epstein**.
Initial speculation among cybersecurity experts linked this incident to a recently confirmed breach involving **IDScan**, an identity verification firm, which resulted in the leak of 153 million driver's licenses. **ShinyHunters** had previously attempted to purchase the **IDScan** database from the original hackers.
**ShinyHunters** has a lengthy history of high-profile attacks. The group recently claimed responsibility for breaches against bank IT provider **Jack Henry** and pharmaceutical/healthcare technology company **McKesson**, where data from oncology and surgical business units was reportedly stolen.
In May, the group caused widespread disruption across the U.S. with an attack on a widely used educational software suite. In April, they stole information from over four million individuals after targeting the world's largest medical device company.
Other notable victims of **ShinyHunters** include **Carnival Cruises**, **Ticketmaster**, **AT&T**, **McGraw Hill**, **ADT**, and gaming company **Rockstar**.
### AI's Role in Cybercriminal Operations
Intriguingly, a report released on Thursday by Artificial Intelligence company **Anthropic** indicated that suspected affiliates of **ShinyHunters** are utilizing AI tools. These tools are reportedly used to scan for credentials, map unfamiliar systems, and steal data from victims for extortion purposes. **Anthropic** noted one instance where an operator transitioned from a stolen developer token to full administrative access within a victim's cloud environment in approximately three hours.
Incident responders at **Google** also confirmed last week that members of the group are employing AI tools from **Anthropic** at various stages of their attacks.
