The ransomware group ShinyHunters says it has infiltrated a Florida government database holding sensitive driver information and stolen more than 200,000 records, according to a report published by CSO Online on September 10. The notorious extortion crew claims to have broken into the Florida Department of Highway Safety and Motor Vehicles' Driver and Vehicle Information Database, known as DAVID, and has set a September 11 deadline for the state to negotiate before releasing the allegedly stolen information. The group posted a screenshot of a record belonging to Jeffrey Epstein as proof, displaying an address, Social Security number, birth date, driver's license number, and registered vehicles.
According to the group's dark web posting, ShinyHunters says it gained entry to DAVID by exploiting a password-reset vulnerability and then took over multiple accounts, including those it claimed were used by DMV employees. The attackers then allegedly searched driver records by identification number and retrieved pages and images. DAVID grants authorized users access to comprehensive driver and vehicle details, meaning a successful break-in could expose far more than just names and license numbers. The alleged breach follows an investigation just days earlier that revealed a separate underground service called Nexus, which offered more than 153 million digital scans of US and Canadian drivers' licenses collected through an identity-verification provider, prompting an FBI probe.
The Florida incident and the Nexus case represent two different sources of license data, the report notes. ShinyHunters claims to have accessed a restricted Florida government database used by law enforcement and other authorized users, while the Nexus database contained scans of government-issued IDs collected by IDScan's identity-verification technology. IDScan.net has formally confirmed its breach, but the Florida DMV has not publicly confirmed the ShinyHunters claim yet. Danny Jenkins, CEO of ThreatLocker, warned that "a complete scan gives criminals much more than an identification number – it can reveal a person's photograph, signature, address, date of birth and other information contained in a legitimate government credential."
If the claims prove accurate, the exposed information could create substantial identity-theft risks because criminals could use the data to open fraudulent accounts, conduct targeted phishing and password-reset attacks, commit insurance, medical, tax or government-benefit fraud, or create convincing synthetic identities, according to the report. The incident aligns with ShinyHunters' typical pay-or-leak strategy, in which the group compromises organizations, shows samples to prove access, and then uses a publication deadline to pressure victims. Past operations include the 2024 Snowflake customer-data campaign, which struck organizations including Ticketmaster, AT&T, and Santander Bank.
The greatest worry is the permanence of the information at risk, Jenkins said. Consumers can replace a credit card or password, but they can't easily replace their face, birth date, signature, or identity history. Jenkins recommended freezing credit, monitoring accounts, and using stronger authentication to reduce risks from the breach. With no public confirmation yet beyond ShinyHunters' dark web claim and its account of how it allegedly carried out the breach, it remains to be seen how the group's September 11 deadline will play out. Organizations facing similar threats may need to weigh the reputational costs of negotiation against the potential harm of wholesale data exposure, particularly when the stolen credentials carry lifelong consequences that no password reset can undo.

