The Florida driver's license system has been hacked, raising concerns about personal data

Reference image created with Artificial Intelligence of a Florida license in front of a cyber alert.Photo © ChatGPT

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed that cybercriminals succeeded in accessing one of its systems using the credentials of a law enforcement employee, in an incident that could have exposed sensitive personal information of drivers in the state.

According to the official statement released by the agency, the authorities became aware of the unauthorized access on September 4 and took action to contain it.

The investigation determined that the attackers used the credentials of an employee from the Plant City Police Department, which had been improperly stored on a personal electronic device.

The affected system was DAVID, the database of drivers and vehicles in Florida, a restricted access platform used by authorized agencies that contains information such as names, Social Security numbers, dates of birth, addresses, photographs, signatures, driving histories, and vehicle data.

According to NBC News, the incident was claimed by ShinyHunters, a well-known group of cybercriminals dedicated to information theft and extortion. The organization published on its dark web site that Florida's vehicle system was among its victims and set September 11 as the deadline to negotiate before allegedly disclosing the obtained data.

As evidence of their alleged access, the group displayed a screenshot that appeared to correspond to the driver's license record of the deceased financier and convicted sex offender Jeffrey Epstein, a former Florida resident. The image included alleged information such as his Social Security number, driver's license, and registered vehicles.

NBC News stated that it could not independently verify the authenticity of that capture.

ShinyHunters claims to have obtained more than 200,000 driver records, but this figure has not been confirmed by the authorities in Florida.

One detail caught attention after the FLHSMV publicly acknowledged the incident. On Friday afternoon, ShinyHunters removed references to Florida from their site.

Ian Gray, Vice President of Intelligence at the threat monitoring company Flashpoint, explained to NBC News that this behavior can occur after interactions between attackers and their victims.

"When a victim does not appear in a blog, it usually means that there was a negotiation," Gray pointed out.

However, there is no public confirmation that Florida has paid a ransom or reached any agreement with the cybercriminals. The FLHSMV did not respond to NBC News when the outlet inquired whether it was engaged in negotiations with the group.

The incident occurs just a few days after another attack related to identification information in the United States was reported.

In early September, IDScan.net, a company that provides identity verification and driver's license scanning services to private businesses, reported that an unauthorized third party may have accessed or copied certain information stored in the cloud accounts of its clients.

Those responsible for the attack claimed to have obtained 160 million identification records, a figure that has not been officially confirmed. Among the supposedly compromised information would be an identification of the U.S. Secretary of War, Pete Hegseth. The FBI has opened an investigation into the incident.

At the moment, there are no public indications that the two attacks are related. However, the cases once again highlight the risks associated with the storage and access of large databases containing personally identifiable information.

Unauthorized access to the DAVID system is particularly significant for Florida, where there is a large Cuban community and where thousands of its members hold driver's licenses and registered vehicles, although authorities have not specified how many individuals were affected or which specific records were compromised.

The FLHSMV reported the incident to the Office of the Attorney General of Florida and is working alongside the Florida Digital Service and the Florida Department of Law Enforcement (FDLE) in the investigation.

Due to the ongoing criminal investigation, the agency stated that it will release additional information when it deems appropriate.

The incident became known days after U.S. authorities opened another investigation related to cybercriminals who attempted to attack hundreds of thousands of accounts on the social network X.

Related videos:

Filed under:

CiberCuba Editorial Team

A team of journalists committed to reporting on Cuban current affairs and topics of global interest. At CiberCuba, we work to deliver truthful news and critical analysis.