$ techbeacon▋
Ransomware

ShinyHunters Extortion Group Allegedly Exfiltrates Over 200,000 Florida DMV Records

ShinyHunters Extortion Group Allegedly Exfiltrates Over 200,000 Florida DMV Records

Cyber‑crime outfit known as ShinyHunters has announced that it penetrated an online platform used by the Florida Department of Motor Vehicles, identified in the group’s communications as "DAVID," and extracted more than 200,000 driver records.

The claim, first reported by security outlet BleepingComputer, includes no independent verification at this stage, but it aligns with a pattern of extortion‑focused groups demanding payment in exchange for withholding stolen personal data. ShinyHunters typically publishes a data dump sample and a ransom note, then threatens to release the full set if the victim does not comply.

Florida’s DMV maintains a massive repository of personally identifying information, such as names, addresses, license numbers, and vehicle details. A breach of that magnitude could expose residents to identity theft, fraud, and phishing attacks, especially if the data are later sold on underground markets.

State officials have not yet confirmed the intrusion, but the Florida Department of Law Enforcement (FDLE) and the agency’s own cybersecurity team are reportedly investigating. Standard protocol after a suspected breach involves isolating the affected system, conducting forensic analysis, and notifying affected individuals if the compromise is substantiated.

Law‑enforcement agencies across the United States have increasingly targeted extortion gangs that leverage stolen data for profit. Recent high‑profile cases, such as the ransomware attacks on municipal services and the exposure of voter registration files, have underscored the growing risk to public‑sector databases. The alleged DAVID breach adds another example of how state‑run services are attractive targets for financially motivated hackers.

While no ransom demand has been disclosed publicly, experts say victims typically face a choice between paying a negotiated sum—often in cryptocurrency—or risking the public release of the data. Authorities generally advise against payment, emphasizing that it encourages further criminal activity and does not guarantee data removal. The outcome of the investigation will determine whether Florida residents receive official breach notifications and what steps will be taken to mitigate potential harm.

Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related