Skip to content
Tech News
← Back to articles

Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

read original get Aura Identity Theft Protection Service → more articles
Why This Matters

This breach highlights how state government databases containing sensitive personal and vehicle data remain vulnerable to attackers who exploit weak endpoint security, like credentials stored on personal devices. It's part of a broader pattern of extortion-driven data breaches where hackers publish stolen records when ransom demands aren't met, exposing consumers to identity theft risks. The incident also underscores how government agencies handle (or mishandle) breach disclosure and accountability.

Key Takeaways
Worth a Look

Aura Identity Theft Protection Service — With driver records, SSNs, and vehicle ownership data now exposed in this breach, monitoring your identity has never been more important. Aura watches for fraudulent use of your personal information and alerts you quickly so you can act before serious damage occurs. It's a practical safeguard for anyone whose data may have been swept up in incidents like this one.

See Aura Identity Theft Protection Service on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

In Brief

The ShinyHunters hacking group has published hundreds of thousands of files from a Florida state database of vehicles and driver information. The hackers said they published the stolen data on its leak site “because the victim did not pay a ransom or cooperate and comply” with the hackers’ demands.

The hackers said they breached the database, known as DAVID, earlier in September and posted as evidence a screenshot purporting to be a record associated with the deceased sex offender Jeffrey Epstein, who had a residence in the state.

The Florida motor vehicle agency, FLHSMV, confirmed a data breach in a statement last week and after the hackers obtained a police officer’s credentials that were stored on a personal device. An agency spokesperson did not respond to TechCrunch’s request for comment on Wednesday about the published data.

According to a copy of the stolen data, which TechCrunch has seen, the hackers stole hundreds of thousands of certificates of vehicle ownership records, which contained vehicle owners’ names and addresses of buyers and sellers. The records also contained vehicle identification numbers.

A smaller number of files included Social Security numbers and other government-issued documents, such as non-U.S. passports and immigration papers but did not appear to contain driver’s licenses or people’s photos.

The driver’s license database breach comes in the same month that a monster hack at identity verification company IDScan allowed hackers to steal over 150 million images of driver’s licenses.