incident-responsetrade-pressNewsThe Broadside2 min read

Florida DMV breached via officer's personal-device credentials

One Plant City cop storing FLHSMV login on a personal device gave ShinyHunters a path in, the credential hygiene failure that compliance teams warn about but can't enforce.


TL;DR

Florida's Department of Highway Safety and Motor Vehicles confirmed Thursday that the ShinyHunters cybercriminal group breached its systems using credentials stolen from a single Plant City Police Department officer who stored them on a personal electronic device. FLHSMV learned of the breach September 4 and is investigating alongside the Florida Digital Service. ShinyHunters had claimed the attack days earlier, posting an alleged DMV record as proof. Anthropic and Google separately reported this week that ShinyHunters affiliates used AI tools to scan for credentials, map systems, and accelerate data exfiltration.

The breach mechanism is the kind of control failure that makes CISOs stare at the ceiling at night. One officer. One personal device. One set of credentials that shouldn't have been there. And an international cybercriminal group walked through the door.

FLHSMV's statement put it plainly: "a criminal actor was able to take advantage of a single Plant City Police Department user's credentials that were improperly housed on the employee's personal electronic device." The department hasn't described what data was accessed or how many people are affected. The only glimpse came from ShinyHunters themselves, who posted what they claimed was the DMV record of Jeffrey Epstein as proof of access.

The IDScan parallel added confusion early in the week. Some experts initially suspected the FLHSMV breach was connected to the 153-million-record IDScan compromise, since ShinyHunters had previously tried to buy that database. The department's Thursday confirmation severs that link, at least for now.

The AI acceleration layer

What distinguishes this incident is the tooling. Anthropic reported Thursday that suspected ShinyHunters affiliates used AI to scan for exposed credentials, map unfamiliar systems, and move from initial access to exfiltration. In one case, an operator went from a stolen developer token to full administrative cloud access in approximately three hours. Google's incident response team confirmed the same pattern last week.

That speed collapses the detection-to-containment window that incident response playbooks assume. A three-hour pivot from token to full admin is not something most municipal SOCs are resourced to catch in time. Credential hygiene (not leaving them on personal devices, not reusing them, not letting them sit unmonitored) becomes the only meaningful defense when the attacker's operational tempo is that fast.

Florida law prohibits government entities from paying ransoms connected to ransomware attacks. This incident isn't ransomware, so that prohibition doesn't directly apply, but the state's exposure is similar: data is out, and there's no straightforward path to getting it back.


Published ·Deep Fathom