Friday Security Briefing: Weekend Attack Alert — ShinyHunters Hits the Florida DMV

WilliamDeShon
2026-09-18 09:00
Friday Security Briefing: Weekend Attack Alert — ShinyHunters Hits the Florida DMV
Katrina's Cyber Corner — Friday Security Briefing header 🔴 Friday Security Briefing

Friday Security Briefing: Weekend Attack Alert — ShinyHunters Hits the Florida DMV

Before you head into the weekend, pull up a chair. This week was a rough one in cybersecurity — and if you run a business of any size, what happened in the last seven days is directly relevant to you. Three major incidents broke this week: a fresh government data breach by one of the most prolific hacking gangs on the planet, an identity document database exposing 150 million Americans' driver's licenses, and ongoing supply-chain attacks that are silently moving through corporate software. Let's talk about what it means for your business.

⚡ This Week's Key Takeaways
  • ShinyHunters breached the Florida DMV on September 16, 2026 — 52GB of compressed state data is now in criminal hands (BitSight Pulse, 2026).
  • IDScan, a national identity-checking company, exposed photos and records of 150 million U.S. and Canadian driver's licenses — the data is already searchable on the dark web (Krebs on Security, 2026).
  • Attacks overwhelmingly spike over long weekends — your most vulnerable window opens tonight at 5 PM and closes Monday morning.

🚨 This Week's Threat: ShinyHunters Just Breached the Florida DMV

In 2026, the ShinyHunters hacking gang has become one of the most destructive criminal groups in operation — and on September 16, just two days ago, they added the Florida Department of Motor Vehicles to their list of victims. According to BitSight Pulse, the breach involved 52 gigabytes of compressed government data. What that data contains — and who will be targeted with it next — is still being determined.

This isn't ShinyHunters' first rodeo this year. The same group breached Instructure's Canvas platform and stole private data on 30 million students, broke into Charter Communications and took 40 million customer records, and compromised Carnival Cruise Lines. Their method is deceptively simple: voice phishing and social engineering. They call your staff, pretend to be IT, and walk right in.

⚠️ Why This Matters to Your Business: The Florida DMV breach means that millions of people's personal details — tied to real identity documents — are circulating among criminal networks right now. Expect a surge in phishing emails, fake invoices, and business email compromise (BEC) attempts this weekend. Your employees are the target.

Meanwhile, the IDScan breach adds another layer of danger. An identity document checking company — the kind used at check-in systems, age-verification portals, and secure access points — was breached over the course of a year. Hackers built a searchable dark web database containing the license photos of 150 million drivers in the U.S. and Canada. If your business uses any identity verification service, you need to ask your provider direct questions about their security posture. Today.

📊 The Numbers You Need to Know This Week

Numbers tell the story better than headlines. Here's the hard data from this week and from 2026's breach landscape so far — context your team needs before Monday.

52 GB
Florida DMV data stolen by ShinyHunters (Sep 16, 2026)
150M
Driver's license records now searchable on the dark web
15M
Patient health records stolen from DentaQuest — 2026's single largest breach
40M
Charter Communications customer records taken by ShinyHunters this year

What these numbers share is a pattern: large, trusted institutions are being breached through human-layer attacks — not exotic zero-day exploits. ShinyHunters doesn't hack your firewall. They call your receptionist. The Klue breach — which affected cybersecurity giants including LastPass, Jamf, and HackerOne — happened because a credential issued in 2022 was never decommissioned. Four years of exposure. One phone call to exploit it.

Small and mid-sized businesses often assume they're below the radar. The data disagrees. Criminal groups use automated tools to scan thousands of businesses simultaneously. The question isn't whether your company is big enough to be targeted. The question is whether you're easy enough to be worth the attempt.

✅ What To Do Before Monday

Here's your no-nonsense action list. Do at least one of these today. Do all five by Monday morning and you'll be meaningfully more protected than 80% of businesses your size.

  • 1 Brief your team on weekend phishing. Send a quick message — even a text — reminding staff not to click unexpected links, respond to urgent financial requests, or share passwords over the phone. ShinyHunters uses voice phishing. Awareness is your first firewall.
  • 2 Enable multi-factor authentication (MFA) on all business accounts. Email, accounting software, cloud storage, CRM — everything. This single step blocks over 99% of automated credential-stuffing attacks. If you already have MFA, verify it hasn't been quietly disabled.
  • 3 Audit any credential older than 12 months. The Klue breach happened because a 2022 credential was never removed. Pull your account list today. Deactivate anything that doesn't need to be active. This takes 15 minutes and can prevent a catastrophic breach.
  • 4 Check if your identity verification provider has issued a security statement. Given the IDScan breach, any service that scans or stores your customers' ID documents may be at elevated risk. Ask directly. Demand transparency.
  • 5 Your one immediate action: Right now, log into your primary business email account and check your active login sessions. If you see devices or locations you don't recognize, revoke access immediately and change your password. Takes 2 minutes. Do it before you close this tab.

🔒 Protect Your Business — Limited-Time Offer

Corporate Cybersecurity Training License

Your team is your biggest security asset — and your biggest vulnerability. Our Corporate Cybersecurity Training License gives your entire staff the knowledge to spot phishing attempts, handle credentials safely, and respond to threats before they become breaches.

Built for business owners and teams. No technical background required.

$1,747

⏰ 30% OFF — Offer ends September 24, 2026

Claim 30% Off Before the Deadline →

I hope you found this week's briefing useful. Threat actors don't take weekends off — but with the right knowledge, neither do you. Stay alert, stay skeptical of unusual requests, and make sure someone on your team knows what to do if something looks wrong.

Have a safe and secure weekend — Katrina, Wealth Horizons Academy Security Advisor

References
1. BitSight Pulse — "Data Breach Tracker 2026: Latest Incidents & Statistics", retrieved 2026-09-18, https://www.bitsight.com/underground/data-breaches
2. TechCrunch / Zack Whittaker — "Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far", retrieved 2026-09-18, https://techcrunch.com/2026/09/15/the-worst-hacks-and-breaches-of-2026-so-far/
3. Krebs on Security — "FBI Probes Service Selling 153M Drivers Licenses", retrieved 2026-09-18, https://krebsonsecurity.com