news.mlab.sh
Back to the feed
threat-intel

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

High
Summary

Florida’s Department of Motor Vehicles suffered a data breach after credentials were stolen from a police officer’s personal device, attributed to the ShinyHunters cybercriminal organization. The group, known for targeting various entities including Jack Henry, McKesson, and Carnival Cruises, has been leveraging AI tools to facilitate their attacks and has a history of exploiting vulnerabilities across multiple sectors. The breach highlights the increasing sophistication of cybercrime and the importance of securing personal devices used for work.

Florida’s Department of Motor Vehicles (FLHSMV) has confirmed a data breach, stemming from stolen credentials accessed from a police officer’s personal device. Officials initially learned of the breach on September 4 and initially blamed it on an unnamed "international cybercriminal organization." The department subsequently confirmed the legitimacy of the breach and is working with the Florida Digital Service to investigate.

ShinyHunters, a cybercriminal organization, claimed responsibility for the breach, sharing alleged photos of DMV records linked to American financier and child sex offender Jeffery Epstein. The group has a documented history of targeting various entities, including Jack Henry, McKesson, and Carnival Cruises, and has been utilizing AI tools to identify and exploit vulnerabilities.

ShinyHunters recently took credit for attacks on bank IT provider Jack Henry as well as pharmaceutical and healthcare technology company McKesson, which told regulators data from their oncology and surgical business units were stolen. The group caused chaos across the U.S. in May with an attack on a widely used educational software suite and stole the information of more than four million people after attacking the world’s largest medical device company in April.

Other victims include AT&T, McGraw Hill and ADT and gaming company Rockstar. Artificial Intelligence company Anthropic released a report on Thursday that said suspected affiliates of ShinyHunters used AI to scan for credentials, map unfamiliar systems and steal data from their victims for extortion. The company said that in one case, an operator moved from a stolen developer token to full administrative access to a victim’s cloud environment in about three hours. Incident responders at Google also confirmed last week that members of the group are using AI tools from Anthropic at various stages of its attacks.

Read the full article at The Record