HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

ShinyHunters Claims Access to Florida DMV Driver Records, Exposing 200K+ Personal Profiles

ShinyHunters says it stole over 200,000 Florida driver records by exploiting a password‑reset weakness. The incident underscores the importance of hardened access‑management controls for audit readiness.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
Medium
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
databreachtoday.com

ShinyHunters Claims Access to Florida DMV Driver Records, Exposing 200K+ Personal Profiles

What Happened — The extortion group ShinyHunters announced that it breached the Florida Department of Highway Safety and Motor Vehicles (DHSMV) database, extracting more than 200,000 driver records that include names, addresses, Social Security numbers, dates of birth, license details, and vehicle registrations. The group says it leveraged a password‑reset vulnerability to compromise employee accounts, enumerate record IDs, and download the data.

Why It Matters for Trust & Control Assurance

  • Demonstrates how weak credential‑reset processes can bypass authentication controls, a classic failure of identity‑and‑access‑management (IAM) governance.
  • Highlights the need for continuous evidence that password‑reset workflows are protected by multi‑factor authentication and robust logging, enabling a defensible audit trail.
  • Aligns with the control objective of “secure access management” that, when satisfied, maps to multiple frameworks (e.g., NIST CSF 2.0, ISO 27001).

Who Is Affected – State government agencies, law‑enforcement partners, and any entity that consumes DHSMV data (e.g., insurance, auto‑finance).

Recommended Actions

  1. Review and harden all password‑reset mechanisms: enforce MFA, rate‑limit attempts, and require privileged approval.
  2. Enable immutable logging of reset requests and account‑access events; feed logs into a continuous‑monitoring platform for real‑time alerts.
  3. Conduct an immediate credential‑access audit and re‑issue compromised credentials.

Technical Notes – The breach vector was a password‑reset vulnerability (details not publicly disclosed) that allowed attackers to obtain valid session tokens for employee accounts. No CVE has been published yet; the flaw appears to be a logic error in the DHSMV’s self‑service portal. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/breach-roundup-shinyhunters-claims-florida-dmv-hack-a-32792

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →