ShinyHunters Claims Breach of Florida DMV Database, Exposing 200,000 Driver Records
The notorious **ShinyHunters** extortion group asserts it has breached the **Florida Department of Motor Vehicles' (DMV)** 'Driver and Vehicle Information Database' (**DAVID**) platform, purportedly stealing over 200,000 driver records. As proof, the group released a screenshot of Jeffrey Epstein's DMV record, detailing sensitive personal information.
The **ShinyHunters** extortion gang has added the **Florida Highway Safety and Motor Vehicles (FLHSMV)** to its data leak site, claiming a significant breach of the state's **DAVID** database.
### DAVID Database Compromised
**DAVID**, or the 'Driver and Vehicle Information Database,' is a critical platform used by Florida law enforcement and officials for immediate retrieval of driver and motor vehicle information. It also serves as the primary reporting mechanism for fatalities and serious bodily injuries.
**ShinyHunters** alleges that it compromised the system, gaining access to over 200,000 records since September 3rd. The group has threatened to leak the stolen data if **FLHSMV** does not engage in negotiations.
### Proof of Breach: Epstein's Record
To substantiate their claims, the threat actors released a screenshot of Jeffrey Epstein's record from the **DAVID** system. This record reportedly includes his address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles. The system also contains tabs for additional details such as driver's license transactions, addresses, insurance, prior vehicles, and parking permits.

### Attack Vector and Scope
**ShinyHunters** informed BleepingComputer that they exploited a password-reset flaw to compromise multiple accounts within the **DAVID** system. These accounts allegedly belonged to DMV employees and an **FBI** agent. Using this access, the attackers iterated through records by ID, downloading associated HTML and images for drivers.
The group claims to have since lost access to the database, and the exploited password-reset flaw is reportedly being patched. Sources also indicate that **ShinyHunters** is targeting other states' DMV platforms using social engineering attacks, with more breaches expected to be announced in the coming weeks.
### Who Are ShinyHunters?
**ShinyHunters** is a prolific extortion gang renowned for targeting online web applications and cloud SaaS environments with data theft attacks. The group has been active since 2018 and has been linked to numerous high-profile breaches.
Initially focusing on platforms like **Salesforce** and other cloud SaaS environments, **ShinyHunters** has expanded its reach, impacting companies such as **Google**, **Cisco**, **PornHub**, and **Match Group**.
The group frequently breaches third-party integration companies, leveraging stolen authentication tokens to access connected SaaS environments and exfiltrate customer data. More recently, **ShinyHunters** has adopted voice phishing (vishing) attacks, impersonating IT support staff to trick employees into divulging credentials and multi-factor authentication (**MFA**) codes on phishing sites.
They have also utilized device code vishing attacks to obtain **Microsoft** account authentication tokens, subsequently hijacking Single Sign-On (**SSO**) accounts to breach services like **Salesforce**, **Microsoft 365**, **Google Workspace**, **SAP**, **Slack**, **Adobe**, **Atlassian**, **Zendesk**, and **Dropbox**.
Notable past attacks include a significant data-theft incident against **Instructure Canvas** in May, which caused widespread outages. **Instructure** reportedly reached an agreement with **ShinyHunters** to prevent the leaked data from being made public.
Despite numerous arrests linked to the **ShinyHunters** name, including suspects connected to the **Snowflake** data-theft attacks and breaches at **PowerSchool**, the group continues to pose a significant threat to enterprises globally.