Skip to content

Security1 publisher3 min readPublished

ShinyHunters claims it scraped 200,000 driver records out of Florida's DAVID lookup portal

The gang says a password-reset flaw handed it DMV employee and FBI accounts, after which it walked record IDs one at a time from September 3. Florida's motor vehicle agency has confirmed none of it, and the proof on offer is one screenshot.

The Watch · Security desk

Illustration accompanying ShinyHunters claims it scraped 200,000 driver records out of Florida's DAVID lookup portal

What happened

  • ShinyHunters listed Florida's Highway Safety and Motor Vehicles agency on its leak site and said it will publish allegedly stolen data unless the agency negotiates.
  • The gang told BleepingComputer it iterated through DAVID records by ID and saved the HTML and images, claiming over 200,000 driver records taken since the run began on September 3.
  • The only public proof so far is a screenshot of Jeffrey Epstein's DAVID record showing his address, Social Security number, birth date, licence details and registered vehicles.
  • FLHSMV and the FBI had not responded to BleepingComputer's questions when the story published, leaving the count and the scope unconfirmed by the victim.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The DAVID field set includes Social Security number, date of birth and licence number, identifiers a driver cannot rotate after disclosure, so if the count holds the liability follows those people for years rather than until a password change.
  • constraint Because the retrieval came through valid law-enforcement logins, nothing at the network edge would have flagged it; catching this class of abuse means baselining per-account lookup volume inside the application itself.
  • decision FLHSMV now faces the negotiate-or-publish choice with a counterparty that got a company to an agreement after the Instructure Canvas theft in May, and a state agency making that call carries different consequences than a vendor making it.
  • precedent With the same crew reportedly social-engineering other states' DMV platforms, credentialed lookup portals move from a records-management problem to a standing extortion target, and other states have to assume they are already in the queue.

A screenshot proves read access to one record [3]. The 200,000 figure rests entirely on the gang's own description of its method, which was to iterate through record IDs and save the returned HTML and images [5]. Those are two separate claims, and only the second one drives a notification count.

Pulling records one at a time means request volume tracks record volume: at least 200,000 authenticated page loads, plus image fetches, against a portal built for looking up one driver at a time [1][8]. BleepingComputer's account says only that multiple accounts were compromised, belonging to DMV employees and an FBI agent [4]. Spread evenly across ten accounts, the run averages 20,000 record views apiece [2]. In a tool whose normal user opens a few dozen records a shift, that shape of query volume is the detection signal, and it sits inside the audit trail of valid law-enforcement logins rather than at any perimeter.

The stated entry path is a password-reset flaw that let the attackers take over accounts [4]. They also say they have since lost access and that the flaw is being patched [6]. Every part of that account comes from the people running the extortion, including the assurance that the door is closed. FLHSMV and the FBI had not responded to BleepingComputer when the story ran [7].

The technique is a departure for this crew. Over the past year the ShinyHunters name has been attached to vishing against Okta, Microsoft and Google SSO accounts, with the callers posing as IT support to harvest credentials and MFA codes [13], and to compromises of third-party SaaS integrations reached with stolen tokens [12]. A password-reset bug in a state agency's web application is a different door into the same business model: bulk records, leak-site listing, negotiation window. FLHSMV was added to that leak site with a threat to publish if it does not negotiate [1]. When the same operation hit Instructure Canvas in May, the company ended up reaching what it called an agreement to keep the data offline [14].

Florida's cost sits partly outside the data. DAVID is FLHSMV's immediate-retrieval system for driver and vehicle information used by law enforcement and criminal justice officials, and the agency describes it as its primary reporting mechanism for fatalities and serious bodily injury [8][9]. Forcing credential resets and access review across that user base is not a background task.

On the multi-state question the evidence is thinner than the headline risk. A source told BleepingComputer that the actors are also going after other states' DMV platforms with social engineering [10], and the gang itself said to expect more breach announcements in coming weeks [11]. Neither is a second confirmed breach. What settles the Florida count is not the leak site but the query logs on the accounts named, and FLHSMV has not published them.

What to watch

  • An FLHSMV statement carrying its own record count and any breach notification filing, which would replace the attacker's number.
  • A second state DMV appearing on the ShinyHunters leak site, which would turn the social engineering reports into a confirmed campaign.
  • Independent confirmation that the password-reset flaw existed and has been fixed, rather than the attackers' word that it is being patched.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories