The notorious extortion gang ShinyHunters claims to have breached Florida's Driver and Vehicle Information Database (DAVID), stealing over 200,000 driver records via a password-reset vulnerability.

  • Over 200,000 driver records stolen from Florida's DAVID database.
  • Attackers leaked Jeffrey Epstein's DMV records as proof of the breach.
  • Breach occurred via a password-reset flaw affecting employees and an FBI agent.
  • ShinyHunters are reportedly targeting other state DMV platforms.

The ShinyHunters extortion gang has sent shockwaves through Florida's administrative infrastructure by claiming a successful breach of the 'DAVID' (Driver and Vehicle Information Database) platform. Operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, DAVID is a critical tool used by law enforcement and criminal justice officials for the immediate retrieval of driver and motor vehicle information.

To validate their claims, the threat actors released a highly sensitive screenshot of Jeffrey Epstein's DMV record. The leaked data includes Epstein's home address, Social Security number, date of birth, driver's license ID, and a detailed list of registered vehicles. The breach also potentially exposed tabs containing insurance details, prior vehicles, and parking permits, highlighting the depth of the intrusion.

Technical Breakdown of the Attack

According to details provided to BleepingComputer, the breach was facilitated by a password-reset flaw. This vulnerability allowed ShinyHunters to compromise multiple high-level accounts, including those belonging to DMV staff and a Federal Bureau of Investigation (FBI) agent. From September 3rd onwards, the attackers iterated through records by ID, downloading HTML pages and images associated with over 200,000 drivers.

Why This Matters

BozokMedia analysis shows that this incident is a textbook example of how a single authentication vulnerability can compromise an entire state-level security apparatus. The fact that an FBI agent's credentials were leaked suggests a systemic failure in identity management. When databases used for 'Fatalities and Serious Bodily Injury (FSBI)' reporting are compromised, it doesn't just risk privacy—it potentially jeopardizes active criminal investigations.

"The shift toward vishing and SSO hijacking by groups like ShinyHunters proves that traditional MFA is no longer a silver bullet for security."

ShinyHunters is far from a novice group. Since 2018, they have evolved into one of the most prolific data theft organizations globally, targeting cloud SaaS environments. Their portfolio of victims includes tech giants such as Google, Cisco, and Match Group. They are known for utilizing 'vishing' (voice phishing) to trick employees into revealing multi-factor authentication (MFA) codes, subsequently hijacking Single Sign-On (SSO) accounts for services like Microsoft 365 and Salesforce.

Recent reports indicate that the gang is currently expanding its campaign to target other state DMV platforms through social engineering. While the attackers claim the password-reset flaw is now being patched and they have lost access, the damage—the theft of 200,000 records—is already done.

Did You Know?: ShinyHunters often targets third-party integration companies to steal authentication tokens, allowing them to bypass primary security layers of major corporations.

Frequently Asked Questions

Q1: What is the DAVID system?
A: DAVID stands for Driver and Vehicle Information Database, a multifaceted platform used by Florida law enforcement for immediate access to driver and vehicle data.

Q2: How did the hackers gain access?
A: They exploited a password-reset vulnerability that allowed them to take over accounts belonging to DMV employees and an FBI agent.