ShinyHunters Claims Theft of 200,000 Records from Florida DMV Database

The ShinyHunters extortion group says it breached Florida's DAVID driver database, stealing over 200,000 records. They exploited a password-reset flaw to compromise accounts, including those of DMV employees and an FBI agent. They posted a screenshot of Jeffrey Epstein's record as proof and threatened to leak data if no negotiation occurs.
The attackers gained entry by exploiting a weakness in the password reset mechanism, allowing them to take over accounts belonging to law enforcement and DMV staff. They systematically queried driver IDs to extract HTML and image files, amassing over 200,000 records before losing access.
The group is known for targeting cloud-based applications and using voice phishing to steal single sign-on credentials. They have previously breached major tech and dating platforms, and now indicate that similar attacks on other state motor vehicle systems are planned.
The exposure of sensitive driver data, including Social Security numbers and addresses, could heighten identity theft and privacy risks for Florida residents. Because the database serves law enforcement, compromised access may undermine trust in official systems. If other states face similar social engineering attacks, the broader public could see increased phishing threats and a need for stronger authentication safeguards across government portals.