>samit_hota
Back to security news

Security News · SN-2026-470

HIGHOPEN

Stolen Credentials on Personal Device Expose Florida DMV Records to ShinyHunters

Affected: Florida Department of Highway Safety and Motor Vehicles (FLHSMV) · Plant City Police Department

Samit Hota·
#news#data-breach#flhsmv

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has publicly confirmed a significant data breach after the extortion group ShinyHunters began shopping access and publishing stolen driver records online. State officials traced the initial point of entry back to an employee at the Plant City Police Department—a municipal agency outside Tampa—who had improperly stored work authentication credentials on an unmanaged personal device.

After detecting unauthorized activity on September 4, state IT personnel launched an investigation alongside the Florida Digital Service. The inquiry determined that an international cybercrime group leveraged the single officer’s compromised login details to gain access to the state’s central motor vehicle database. ShinyHunters subsequently published photos of sensitive driver license entries—including that of high-profile convict Jeffrey Epstein—to validate their access.

How Infostealers and Unmanaged Devices Bypassed Perimeter Security

The root cause of the initial access points directly to the persistent threat posed by consumer-targeted infostealer malware (such as RedLine, Lumma, or Raccoon). When employees log into enterprise systems or state databases from personal computers, browser credential managers often save plaintext passwords and session cookies. Once an infostealer infects the personal host through malicious ad campaigns, cracked software, or phishing, threat actors extract saved credentials and session tokens, effectively neutralizing password-based controls.

In this instance, the Plant City police officer’s login granted broad query access to the state DMV database. Partner agencies often maintain API or web portal connectivity to retrieve driver histories, registration details, and personally identifiable information (PII) during traffic stops and investigations. Because the compromised account held legitimate query permissions, initial malicious requests blended into routine background traffic, delaying detection until anomalous data exfiltration patterns or external exposure alerted security personnel.

Attribution to ShinyHunters and the Modern Extortion Model

ShinyHunters is a well-established cybercrime organization notorious for large-scale data theft and extortion. The group gained notoriety through high-volume breaches targeting consumer, financial, and healthcare platforms, including recent campaigns involving jack Henry, healthcare tech giant McKesson, Ticketmaster, AT&T, ADT, McGraw Hill, and gaming provider Rockstar.

Initially, security analysts suspected the Florida DMV leak might be connected to an earlier incident involving identity verification vendor IDScan, which compromised 153 million driver’s license records. ShinyHunters had publicly attempted to purchase the IDScan database from third-party hackers. However, the FLHSMV’s internal investigation confirmed that this incident was distinct, resulting from direct unauthorized database queries using the stolen police credentials rather than a third-party supply chain leak.

The Role of AI in Rapid Privilege Escalation

This intrusion highlights a alarming operational trend in threat actor tactics: the integration of generative AI tools to accelerate post-compromise activity. A report published by Anthropic, supported by independent observations from Google’s incident response teams, confirmed that ShinyHunters affiliates are utilizing advanced AI models during active operations.

Rather than manually navigating unfamiliar active directories or cloud environments, operators feed stolen authentication tokens, script outputs, and network maps into AI workflows. The AI assists attackers by rapidly scanning for exposed credentials, mapping permission hierarchies, and identifying high-value data repositories. In observed cases, attackers leveraged stolen developer tokens to achieve full administrative access over victim cloud environments in approximately three hours—a process that historically took days of manual reconnaissance.

Blast Radius and Systemic Access Risks

State motor vehicle databases represent critical single points of failure for public PII. A compromised DMV system exposes full names, residential addresses, dates of birth, driver license numbers, photos, and potentially social security numbers for millions of citizens. Beyond the immediate identity theft and targeted phishing risks to residents, public-facing database leaks undermine law enforcement confidentiality and cross-agency trust networks.

The systemic issue lies in federated trust models. Municipal law enforcement agencies across Florida require legitimate access to FLHSMV systems, but individual municipal departments vary wildly in their endpoint management capabilities, BYOD policies, and multi-factor authentication enforcement. A single weak endpoint at a small suburban police department can compromise a central repository serving tens of millions of people.

Mitigating Credential Theft and Unmanaged Endpoint Exposure

Organizations maintaining federated access to centralized state or corporate databases must eliminate relying solely on static, password-based authentication from unmanaged devices.

To mitigate credential theft via infostealers, enterprise environments should enforce strict device posture checks prior to granting session access. Implementing Zero Trust Network Access (ZTNA) or Conditional Access policies ensures that accounts can only authenticate from managed, compliant devices equipped with Endpoint Detection and Response (EDR) agents. Furthermore, hardware-backed multi-factor authentication (such as FIDO2/WebAuthn security keys) prevents stolen browser cookies or passwords from being reused on unauthorized systems. State and municipal agencies must also audit cross-organizational API access, enforcing strict rate-limiting and behavior-based anomaly detection to catch automated data harvesting before massive exfiltration occurs.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call