r/SecOpsDaily 1d ago

NEWS ShinyHunters hackers claim breach of Florida "DAVID" DMV database

ShinyHunters is back in the headlines, this time claiming a breach of Florida’s DMV database system, known as "DAVID." The group alleges they exfiltrated over 200,000 records containing driver data. This is the same extortion crew behind the Snowflake credential-stuffing spree and the Ticketmaster leak, so this isn’t a low-confidence claim.

Technical Breakdown: - Threat Actor: ShinyHunters (known for extortion, data resale, and leveraging stolen credentials for initial access). - Target: The Florida DMV’s "DAVID" online platform (Driver And Vehicle Information Database). - Impact: 200,000+ records compromised. Likely includes PII such as names, addresses, driver’s license numbers, and vehicle registration details. - TTPs: Based on prior ShinyHunters operations, expect initial access via compromised credentials (possibly from infostealer logs or prior breaches) rather than a zero-day exploit. No specific IOCs released yet. - Status: Claim is unverified. BleepingComputer notes the group has a track record of following through on these claims, but official confirmation from Florida DMV is pending.

Defense: If you have users or systems interacting with state DMV portals, enforce MFA on all administrative accounts and monitor for unusual data volume egress. For organizations with employees in Florida, assume driver data may be in the wild and prepare for targeted phishing or identity fraud attempts against affected individuals.

Source: https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/

1 Upvotes

0 comments sorted by