ShinyHunters dumps Florida driver database after ransom refusal

A police officer left their credentials on a personal device. That single lapse is now why hundreds of thousands of Florida residents have their home addresses, vehicle details, and in some cases Social Security numbers floating around on a hacker leak site.

The ShinyHunters group has published a massive tranche of files stolen from Florida’s DAVID database, a state-run system holding driver and vehicle records. As reported by TechCrunch, the group says it went public with the data because the victim refused to pay a ransom or cooperate with their demands. That’s how these groups operate: the breach is the leverage, and publication is the punishment for non-compliance.

The Florida Highway Safety and Motor Vehicles agency confirmed the breach last week. What it has not done is answer questions about the data that’s now been published. That silence is a problem. When a government agency holds this much sensitive information and gets breached, residents deserve more than a confirmation statement and a wall of no-comment.

According to TechCrunch, which reviewed a copy of the stolen data, the files include hundreds of thousands of vehicle ownership certificates containing the names and addresses of both buyers and sellers, along with vehicle identification numbers. A smaller subset of records also includes Social Security numbers, non-U.S. passports, and immigration documents. Driver’s license images do not appear to be part of what was published, but that’s a narrow comfort when SSNs and home addresses are already out.

The hackers claim they breached the database earlier in September and posted a screenshot of an Epstein-linked record as proof of access. Whether that specific detail is true or theater, it worked as a headline grab. The real story is the exposure of ordinary people who had no choice but to hand this data to the state.

This breach does not happen in isolation. September alone has seen the IDScan hack expose over 150 million driver’s license images from an identity verification company. Two major incidents in the same month, both targeting government-adjacent identity data, both hitting people who never consented to their information being a target. That’s the pattern worth watching.

State motor vehicle databases are goldmines for fraud. Names, addresses, vehicle details, and immigration status documents in one place is exactly what identity thieves need. The fact that a single compromised credential on a personal device opened the door to all of this points to a deeper problem: government agencies managing critical infrastructure with security practices that would be unacceptable in the private sector.

If you’re a Florida resident, assume your vehicle ownership data has been exposed. Check your credit, watch for phishing attempts that reference your address or vehicle, and consider a credit freeze if your SSN was among the smaller set of records included.