Scans of passports, driver’s licenses and Social Security cards are among the more than half-million documents leaked Monday following a hack of the Florida Department of Highway Safety and Motor Vehicles.
The hacker group known as “ShinyHunters” released a downloadable archive of the data on the dark web. The release apparently came after the hackers demanded payment from the state.
“State of Florida failed to reach an agreement with us despite our incredible patience, all the chances and offers we made,” the hackers wrote. “They don’t care.”
Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.™
Point phone camera here
Epstein record leaked
The hackers released the full dataset a week after announcing the breach in a post online that included a photo of deceased sex offender and former Florida resident Jeffrey Epstein’s driving record. The group had threatened to release the full data cache unless Florida paid an undisclosed ransom by Friday.
Epstein’s record included a wide range of personal data such as an ID number, home address, physical characteristics and Social Security Number.
It listed several vehicles — two Harley-Davidson motorcycles, a Mercedes-Benz, a Chevrolet and a Volkswagen convertible — along with the tag and VIN numbers.
Under a photograph and signature of Epstein, the term “Sexual Offender” was written in red. Another label indicated that the record is expired.
Documents date back to 1990s
The motor vehicles department confirmed in a statement on Thursday that a data breach had occurred after “a criminal actor was able to take advantage of a single Plant City Police Department user’s credentials that were improperly housed on the employee’s personal electronic device.”
A Straight Arrow analysis of the hacked data found a wide range of sensitive identifying documents, such as passports issued as far back as the 1990s. Many of the scans also showed documents related to non-citizens, such as permanent resident cards, visas, resident alien cards, employment authorization cards and refugee travel documents.
IDs in the breach originate from numerous countries, including Canada, Venezuela, Egypt, Uruguay, Cuba, Brazil, China, India and Colombia.
Driver’s license photos, alongside their accompanying signatures, are also abundant. Vehicle titles, certificates of origin, odometer verification documents and transfer applications were found throughout the data cache as well.
While 475,207 of the files were images, the other 119,494 were downloaded HTML web pages containing individual driving records. The records, taken from Florida’s Driver and Vehicle Information Database, known as DAVID, includes names, Social Security numbers, home addresses, dates of birth and whether a driver has had a DUI, among other information.
ShinyHunters, which has been active since 2019, has previously taken credit for high-profile breaches against companies such as PornHub and Vimeo.
The leak comes roughly two weeks after an unknown hacker group began selling access to 170 million identity documents on the dark web following their breach of a major ID verification service.
