ZCyberNews
中文
Industry News4 min readShinyHunters

Florida DMV Breach Tied to ShinyHunters, Stolen Officer Credentials

ShinyHunters breached the Florida DMV after a Plant City officer's login sat on a personal device. The state confirmed the claim on September 10 after days of silence.

Illustration of a state motor vehicle records database accessed through stolen login credentials.

Executive Summary

ShinyHunters obtained access to Florida motor vehicle records using credentials that a Plant City police officer had stored on a personal device, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed on September 10. The confirmation came four days after the cybercriminal group publicly claimed the intrusion and after the department declined repeated requests for comment during the intervening week.

The incident is the latest in a run of ShinyHunters campaigns against large U.S. organizations, and it illustrates a recurring pattern for the group: a single set of valid credentials, not a software exploit, opening the door to a high-value data store. For defenders, the case reinforces that identity sprawl — logins living outside managed endpoints — remains a direct path to bulk record theft.

Technical Analysis

FLHSMV said it first learned of the breach on September 4 and attributed it to an unnamed "international cybercriminal organization." Its investigation concluded that a criminal actor used credentials belonging to a single Plant City Police Department user that were "improperly housed on the employee's personal electronic device." Plant City is a small suburb outside Tampa.

The department has notified other Florida government offices and is working with the Florida Digital Service on the investigation. It did not disclose the number of records affected or the specific data fields exposed.

ShinyHunters surfaced its claim on Monday, September 7, and offered proof of access by sharing what it said were photos of a DMV record tied to financier and convicted sex offender Jeffrey Epstein. The group has not published a broader data sample or a leak-site count.

When the claim first appeared, some security researchers suspected a connection to the recently confirmed breach at identity verification firm IDScan, which exposed 153 million driver's licenses. ShinyHunters had previously sought to buy that ID database from the hackers behind the IDScan incident. The Florida confirmation describes a different initial access vector — stolen endpoint credentials — so the two events appear distinct on the available evidence, though neither the state nor the group has published forensic detail that would rule out overlap.

The breach fits a broader ShinyHunters tempo in 2026. The group most recently claimed attacks on bank IT provider Jack Henry and on pharmaceutical and healthcare technology company McKesson, which told regulators that data from its oncology and surgical business units was stolen. Other named victims this year include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar. In May the group disrupted a widely used educational software suite, and in April it stole information on more than four million people after attacking the world's largest medical device company.

Separately, Anthropic published a report on September 10 stating that suspected ShinyHunters affiliates used its AI models to scan for credentials, map unfamiliar systems, and exfiltrate data for extortion. Anthropic said one operator moved from a stolen developer token to full administrative access to a victim's cloud environment in roughly three hours. Google incident responders confirmed the prior week that group members were using Anthropic's tools at various stages of their attacks.

Mitigations & Recommendations

The Florida case points to a control gap that policy alone rarely closes: privileged or sensitive logins stored on unmanaged personal devices. Agencies and contractors should inventory accounts with access to motor vehicle, identity, or citizen-record systems and verify that credentials for those accounts are not resident on personal hardware. Where personal-device use is unavoidable, require phishing-resistant MFA and device-bound credentials so a copied password alone is insufficient.

Because ShinyHunters has repeatedly converted valid credentials into bulk exfiltration, monitoring should focus on anomalous authentication and data-access patterns rather than malware signatures — for example, first-time logins from unfamiliar geographies, bulk record queries by accounts that normally touch few records, and developer tokens being used to enumerate cloud permissions. The Anthropic reporting suggests affiliates use AI to accelerate exactly this reconnaissance, which compresses the window between initial access and exfiltration.

Stay Updated

Get the latest cybersecurity news delivered to your inbox.

Related Articles