State authorities in Florida disclosed Thursday that the Department of Motor Vehicles fell victim to a data breach after an officer's access credentials were compromised through storage on a personal device.

The ShinyHunters cybercriminal group announced Monday that they had breached the Florida Department of Highway Safety and Motor Vehicles (FLHSMV). Though the department initially declined to comment, it issued a public acknowledgment of the breach Thursday evening.

The breach came to light on September 4, with officials initially attributing it to an unidentified "international cybercriminal organization." In a subsequent statement, the department explained: "The Department immediately launched an investigation, which determined that a criminal actor was able to take advantage of a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device."

Plant City, situated as a small suburb near Tampa, is where the compromised officer worked. The FLHSMV has since notified other state government agencies and enlisted the Florida Digital Service to assist with the investigation.

To substantiate their claims, ShinyHunters distributed purported images from DMV records belonging to financier and convicted sex offender Jeffrey Epstein.

When the breach first surfaced, some security researchers speculated a connection to the separate incident involving IDScan, an identity verification company that had 153 million driver's licenses exposed. ShinyHunters had previously sought to acquire that stolen ID database from the IDScan attackers.

ShinyHunters' broader attack history

The group has claimed responsibility for numerous high-profile intrusions in recent months. Their targets have included Jack Henry, a bank IT provider; McKesson, a pharmaceutical and healthcare technology firm that reported data theft from its oncology and surgical divisions; and a widely deployed educational software platform that caused disruption across the United States in May.

Additional victims span multiple sectors and include the world's largest medical device manufacturer, which suffered a breach in April affecting over four million individuals. The group has also targeted Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar.

AI-powered attack tactics

Anthropic, an artificial intelligence company, released findings Thursday indicating that suspected ShinyHunters associates have deployed AI tools to identify credentials, analyze unfamiliar infrastructure, and extract data for extortion schemes. According to the report, one operator escalated from a compromised developer token to complete administrative control of a victim's cloud infrastructure in approximately three hours.

Google's incident response team independently verified last week that ShinyHunters members are leveraging Anthropic's AI tools throughout multiple phases of their attack operations.

Source: The Record