ShinyHunters Exploits Stolen Credentials from Officer's Personal Device to Breach Florida DMV
The Florida Department of Motor Vehicles has confirmed a data breach resulting from credentials stolen from a police officer's personal device, attributed to the ShinyHunters cybercrime group.

Florida officials confirmed on Thursday that the state's Department of Motor Vehicles (DMV) suffered a significant data breach. The incident occurred after login credentials belonging to a police officer were compromised due to being stored on the officer's personal electronic device. This breach highlights a critical vulnerability stemming from the improper handling of sensitive access information on non-work-issued equipment.
The ShinyHunters cybercriminal organization claimed responsibility for the attack on Monday, asserting they had gained access to data from the Florida Department of Highway Safety and Motor Vehicles (FLHSMV). While the department initially remained silent, it publicly acknowledged the breach on Thursday night, confirming its legitimacy. The FLHSMV first became aware of the incident on September 4 and initially attributed it to an unnamed "international cybercriminal organization."
An investigation by the department revealed that a "criminal actor was able to take advantage of a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device," according to a statement. Plant City is a small suburb located outside of Tampa. In response, the FLHSMV has notified other state government offices and is collaborating with the Florida Digital Service to thoroughly investigate the breach.
As evidence of their intrusion, the ShinyHunters group released alleged images of DMV records connected to financier and convicted sex offender Jeffery Epstein. Initially, some cybersecurity experts speculated that this breach might be linked to the recent compromise involving 153 million driver's licenses leaked by the identity verification firm IDScan, as ShinyHunters had previously expressed interest in purchasing that database.
ShinyHunters has been active recently, claiming responsibility for attacks on various entities. These include the bank IT provider Jack Henry and the pharmaceutical and healthcare technology company McKesson, which reported that data from its oncology and surgical business units was stolen. The group also caused widespread disruption in May with an attack on a popular educational software suite and exfiltrated data from over four million individuals after compromising the world's largest medical device company in April. Other notable victims include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and the gaming company Rockstar.
Adding to the concern, a report released by Artificial Intelligence company Anthropic indicated that suspected affiliates of ShinyHunters are leveraging AI tools to scan for credentials, map unfamiliar systems, and steal data for extortion. Anthropic detailed one instance where an operator escalated from a stolen developer token to full administrative control of a victim's cloud environment in approximately three hours. Google's incident responders have also corroborated that members of the ShinyHunters group are employing AI tools from Anthropic across various stages of their attack lifecycle.
This incident underscores the persistent threat posed by credential theft and the evolving tactics of cybercriminal groups like ShinyHunters. The reliance on personal devices for work-related credentials and the increasing use of AI by threat actors present significant challenges for organizations seeking to protect sensitive data.