Hackers Claim Breach of Florida DMV Database, Demand Ransom
AI-generated from multiple sources. Verify before acting on this reporting.
TALLAHASSEE, Fla. — A cybercriminal group known as ShinyHunters claimed on Monday to have breached the Florida Department of Motor Vehicles' internal DAVID database, stealing more than 200,000 driver records in an act of digital extortion.
The gang announced the intrusion late Monday afternoon, asserting that they had successfully infiltrated the state agency's systems and exfiltrated sensitive personal data belonging to Florida residents. The stolen information reportedly includes names, addresses, dates of birth, and driver license details, which the group indicated could be used for identity theft or sold on dark web marketplaces if their demands are not met.
The DAVID database is a critical component of Florida's motor vehicle infrastructure, storing comprehensive records used for licensing, registration, and law enforcement verification. A breach of this magnitude represents a significant security failure for the state agency, which manages millions of driver files annually.
ShinyHunters has a history of targeting government entities and large corporations with ransomware attacks followed by public threats to release stolen data. In this instance, the group stated they are seeking payment to prevent the public release of the compromised records. They warned that failure to negotiate would result in the data being dumped online, potentially exposing hundreds of thousands of citizens to fraud.
Florida Department of Motor Vehicles officials have acknowledged the incident but provided limited details regarding the scope of the breach or the specific vulnerabilities exploited. The agency stated it is actively investigating the intrusion and working with federal cybersecurity partners to contain the threat and secure its networks. No confirmation has been issued regarding whether the data remains under the hackers' control or if any records have already been made public.
State lawmakers are expected to call for an immediate review of the DMV's cybersecurity protocols following the announcement. The incident comes at a time when state agencies across the United States face increasing pressure from organized cybercrime syndicates seeking to monetize government data.
The Florida Department of Law Enforcement has not yet commented on whether criminal charges have been filed or if any arrests are imminent in connection with the attack. Authorities have advised residents to monitor their credit reports and personal accounts for signs of unauthorized activity, though no specific instructions regarding identity protection services have been released.
As of late Monday, it remains unclear how long the hackers had access to the DAVID system before the breach was detected, or whether the 200,000 records represent the full extent of the theft. The situation is developing as state officials work to assess the damage and determine the next steps in their response to the extortion attempt.