BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Sep 11, 2026 · 2 min read · Original story

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

Officials in Florida said Thursday the state Department of Motor Vehicles suffered a data breach after credentials were stolen from a police officer who had his login information on a personal device.

On Monday, the ShinyHunters cybercriminal organization claimed they obtained access to data from the Florida Department of Highway Safety and Motor Vehicles (FLHSMV).

The department did not respond to repeated requests for comment throughout the week but on Thursday night, it publicly confirmed the legitimacy of the breach.

Officials initially learned of the breach on September 4 and blamed it on an unnamed “international cybercriminal organization.”

“The Department immediately launched an investigation, which determined that a criminal actor was able to take advantage of a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device,” the department said.

Plant City is a small suburb outside of Tampa. FLHSMV has notified other Florida government offices and is partnering with the Florida Digital Service to investigate the breach.

As proof of their access, the ShinyHunters group shared alleged photos of the DMV record tied to American financier and child sex offender Jeffery Epstein.

When the claims of the breach initially emerged, some cybersecurity experts believed it was tied to the recently confirmed breach involving the 153 million driver’s licenses leaked by identity verification firm IDScan. ShinyHunters had previously asked to purchase the ID database from the hackers behind the IDScan breach.

The group most recently took credit for attacks on bank IT provider Jack Henry as well as pharmaceutical and healthcare technology company McKesson, which told regulators data from their oncology and surgical business units was stolen.

The group caused chaos across the U.S. in May with an attack on a widely used educational software suite and stole the information of more than four million people after attacking the world’s largest medical device company in April.

Other victims include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill and ADT and gaming company Rockstar.

Artificial Intelligence company Anthropic released a report on Thursday that said suspected affiliates of ShinyHunters used AI to scan for credentials, map unfamiliar systems and steal data from their victims for extortion. The company said that in one case, an operator moved from a stolen developer token to full administrative access to a victim’s cloud environment in about three hours.

Incident responders at Google also confirmed last week that members of the group are using AI tools from Anthropic at various stages of its attacks.

References in this story

  1. FLHSMV (@FLHSMV) on X x.com On September 4, 2026, FLHSMV learned of a data breach conducted by an international cybercriminal organization. The data breach was quickly mitigated and no further breach has occurred or is ongoing. The Department…
  2. Dark Web Informer (@DarkWebInformer) on X x.com ‼️ The DL sample made publicly on ShinyHunters pay or leak site is Jeffrey Epstein.
  3. IDScan confirms breach after hackers offer 153 million driver’s license scans for sale therecord.media A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.
  4. Dark Web Informer (@DarkWebInformer) on X x.com ‼️ ShinyHunters has a message for the actor who setup shop on 153M US drivers licenses for sale... "We've been trying to get ahold of you. We've made you several large offers for the data you possess (DL data). We don't…
  5. Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack therecord.media The pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.
  6. Instructure pays ransom after Canvas incident as Congress announces investigation therecord.media The company said its agreement with the hackers involved their data being “returned” to them and digital confirmation of data destruction.
  7. Major medical device manufacturer notifies nearly 4 million of breach therecord.media Information like Social Security numbers and health-related data was accessed, but the company said it had “no evidence that impacted information has been publicly posted or exposed on the internet.”
  8. Cruise giant Carnival confirms data breach affecting nearly 6 million people therecord.media The company said the threat actor gained access to a limited portion of its IT environment last month after compromising an employee account. By the end of April, Carnival determined that the attacker had copied…
  9. Live Nation confirms Ticketmaster breach after hackers hawk stolen info of 560 million therecord.media The company has confirmed that the leaked data was from a database hosted on Snowflake — one of the largest cloud storage companies.
  10. Hackers stole ‘nearly all’ call logs over six months from AT&T therecord.media The telecom giant said the massive breach involving logs from 2022 occurred through the third-party cloud platform Snowflake.
  11. Educational company McGraw Hill says Salesforce misconfiguration led to data leak therecord.media The data breach emerged this weekend when the ShinyHunters cybercriminal organization claimed to have stolen 45 million Salesforce records and threatened to leak the information by April 14 if a ransom was not paid.
  12. ADT says customer data stolen in cyber intrusion therecord.media The home security company ADT said cybercriminals breached company systems on Monday and stole a “limited set” of customer and prospective customer information.
  13. Hackers claim breach of Rockstar Games via cloud analytics platform therecord.media The ShinyHunters cybercrime group has claimed responsibility for breaching systems linked to video game developer Rockstar Games, threatening to release stolen data if a ransom is not paid.
  14. Anthropic caught Russia-linked spies using Claude in hacking operations therecord.media Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.
  15. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  16. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  17. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  18. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

← Back to all news