ShinyHunters posts Florida driver data after breach

Hackers say they leaked files from Florida’s DAVID system after ransom demands were not met. The records include vehicle ownership data and some sensitive IDs.
ShinyHunters has published a large batch of files stolen from a Florida state database containing vehicle and driver information, saying the data was released after the victim did not pay a ransom or meet its demands. The leak is drawing attention because the exposed records include vehicle ownership information tied to named individuals, along with some more sensitive personal documents. Florida’s motor vehicle agency, FLHSMV, had already confirmed a breach last week. The agency said attackers got in using a police officer’s credentials that were stored on a personal device.
The hackers also said they breached the database, known as DAVID, earlier in September and posted a screenshot they claimed showed proof of access. As IT-PUB News notes, the source material does not independently verify the group’s account of why the files were published, but that claim is central to how ShinyHunters framed the leak.
ShinyHunters says DAVID files include ownership records
TechCrunch said it reviewed a copy of the stolen data. Based on that material, the hackers obtained hundreds of thousands of certificates of vehicle ownership records. Those files included the names and addresses of vehicle buyers and sellers, as well as vehicle identification numbers.
That combination makes the leak more serious than a routine administrative exposure. Vehicle ownership records can connect a person to a specific car and a home address, making the data more useful for tracking, targeting, or identity-related abuse than a simple list of registrations.
The hackers said they posted the files on their leak site because the victim “did not pay a ransom or cooperate and comply” with their demands.
Some leaked files reportedly contain Social Security numbers
Alongside the ownership records, a smaller set of files reportedly contained Social Security numbers and other government-issued documents. Those included non-U.S. passports and immigration papers.
The stolen material did not appear to include driver’s licenses or people’s photos. That matters because it suggests the breach exposed personal and administrative records, rather than the full set of identity documents that may have been stored in the system.
Still, the presence of Social Security numbers and other official papers raises the stakes. Information like that can be far more sensitive than vehicle data on its own, especially when combined with names, addresses, and other identifying details.
FLHSMV says stolen police credentials were used
FLHSMV confirmed last week that it had suffered a data breach. The agency said the incident followed the theft of a police officer’s credentials, which had been stored on a personal device.
It points to a familiar security weakness: attackers do not always need to break directly into a protected database if they can get valid login details from somewhere else. In this case, the source text does not say how the credentials were obtained, only that they were stored on a personal device and then used to gain access.
An agency spokesperson did not respond to TechCrunch’s request for comment on Wednesday about the published data. No further response from FLHSMV appears in the source material.
The leak comes amid a broader run of driver ID breaches
The Florida breach did not happen in isolation. The source notes that it came in the same month as a major hack at identity verification company IDScan, where hackers allegedly stole more than 150 million images of driver’s licenses.
That timing puts the Florida incident in a broader context. Driver and vehicle records are valuable targets because they can help verify identity, document ownership, or support other forms of fraud. When several incidents involving similar data happen close together, concern extends beyond one agency or company to anyone whose personal information may be sitting in related systems.
The case also reflects a common tension in cyber extortion attacks. Attackers threaten to publish stolen data, while victims must decide whether to pay, negotiate, or refuse. Here, ShinyHunters says the leak followed unmet demands.
For people whose records were included, the impact depends on exactly what was exposed. Vehicle ownership files can show where someone lives and what they drive. More sensitive documents, if authentic and usable, could create additional risks. The source does not say how many people were affected overall, but the size of the file dump suggests the breach is substantial.
The incident is also a reminder that public-service databases holding routine records can expose highly personal information when access controls fail. Even without full driver’s licenses or photos, names, addresses, vehicle details, and selected government documents are enough to make this leak a serious one.