ShinyHunters Hackers Claim Breach of Florida "DAVID" DMV Database
ShinyHunters Hackers Claim Breach of Florida “DAVID” DMV Database
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as “DAVID” and stole over 200,000 records about drivers in the state. 🚨
DAVID is the Driver and Vehicle Information Database platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver. As proof of the breach, the threat actors released a screenshot of Jeffrey Epstein’s record in the DAVID system, which includes the person’s address, Social Security number, birth date, driver’s license ID, issuance and expiration dates, and registered vehicles.
Last night, ShinyHunters added FLHSMV to its data leak site, warning that it would leak the allegedly stolen data if the agency did not negotiate with them. ShinyHunters told BleepingComputer they breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system, which allegedly belonged to DMV employees and an FBI agent. Using this access, the threat actors say they iterated through the records by IDs and then downloaded the associated HTML and images for the drivers, allegedly allowing them to steal over 200,000 data records since the breach began on September 3rd.
The threat actors told BleepingComputer that they have since lost access to the database and that the password-reset flaw used to compromise accounts is being patched. A source told BleepingComputer that the threat actors are also targeting other states’ DMV platforms using social engineering attacks. When asked whether they are targeting additional DMVs, ShinyHunters told BleepingComputer they expect to announce other breaches over the coming weeks.
ShinyHunters is an extortion gang known for targeting online web applications and cloud SaaS environments in data theft attacks. Over the past year, threat actors using the ShinyHunters name have become one of the most prolific groups that conduct data theft and extortion attacks against companies worldwide. Initially focusing on Salesforce and other cloud SaaS environments, the threat actors are linked to a growing number of breaches involving companies such as Google, Cisco, PornHub, and online dating giant Match Group.
More recently, the threat actors have been conducting voice phishing (vishing) attacks targeting Okta, Microsoft, and Google single sign-on (SSO) accounts, where they impersonate IT support staff to trick employees into entering credentials and multi-factor authentication (MFA) codes on phishing sites. After stealing credentials and authentication codes, the threat actors hijack SSO accounts to breach connected enterprise services such as Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Adobe, Atlassian, Zendesk, and Dropbox. Even with numerous arrests linked to the ShinyHunters name, threat actors using the ShinyHunters name remain a threat to enterprises worldwide.