The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed a data breach, attributing it to credentials stolen from a Plant City Police Department officer's personal electronic device. The department initiated an investigation on September 4 after discovering the incident.
The cybercriminal group ShinyHunters claimed responsibility for the breach on Monday, stating they had accessed FLHSMV data. As evidence, the group reportedly shared images of a Department of Motor Vehicles record associated with financier Jeffery Epstein.
FLHSMV officials confirmed the breach on Thursday, stating that a "criminal actor was able to take advantage of a single Plant City Police Department user’s credentials that were improperly housed on the employee’s personal electronic device." Plant City is a suburb of Tampa. The department is collaborating with the Florida Digital Service and has informed other Florida government offices about the incident.
Initially, some cybersecurity experts speculated that this breach might be connected to a recently confirmed leak of 153 million driver’s licenses from the identity verification firm IDScan. ShinyHunters had previously sought to acquire the ID database from the perpetrators of the IDScan breach.
ShinyHunters has been linked to several high-profile attacks this year. In May, the group targeted an educational software suite, impacting over four million individuals. In April, they attacked a major medical device company. Other reported victims include bank IT provider Jack Henry, pharmaceutical and healthcare technology company McKesson (from which data from oncology and surgical units was reportedly stolen), Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar.
Recent reports from artificial intelligence company Anthropic and incident responders at Google indicate that suspected affiliates of ShinyHunters are employing AI tools in their operations. These tools are reportedly used to scan for credentials, map unfamiliar systems, and exfiltrate data for extortion purposes. In one instance, an operator allegedly escalated from a stolen developer token to full administrative access within a victim's cloud environment in approximately three hours.






