A criminal crew broke into Florida's DMV database and proved it by leaking Jeffrey Epstein's driver record. They didn't hack the system. They used a police login stored on a personal device. If one stolen password can open a government database, what does that say about the logins running your business?
Your security is only as strong as the login you handed someone else.
Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's cyber stories for executives, owners, and operators who can't afford to be blindsided.
First, Florida. The state confirmed its DAVID driver database was breached after a crew called ShinyHunters used login credentials stolen from a single police officer. Those credentials were stored on the officer's personal device. The group claims it took more than 200,000 driver records. Full names, addresses, dates of birth, and license numbers can fuel identity theft and fraud for years. This wasn't a genius hack. It was one careless login. That's what should scare every business owner.
Next, Trezor. The company makes hardware wallets designed to keep crypto offline and safe, yet 347,000 newsletter subscribers received a phishing email that sailed past every spam filter. It came through Trezor's own account after attackers breached Brevo, the marketing platform Trezor uses to send email. The message faked an urgent security alert to trick people into surrendering the secret backup that unlocks their crypto. BitBox and CoinTracking were hit through the same vendor. Trezor killed the fake link in about 20 minutes, but 2,500 people had already clicked. Your customers can be attacked through your brand even when everything you control is locked down.
Finally, Interim HealthCare. The home-health provider operates across more than 40 states, and two separate ransomware gangs claimed they hit it this summer. Genesis said it took a full terabyte of medical records and patient data. Anubis claimed a separate haul of franchisee financials and internal audits. When the ransom went unpaid, the data was leaked anyway. Paying a criminal buys a promise, not your privacy back. If you run multiple locations, the attacker only needs your weakest one.
In this episode, we discuss:
• How a police login stored on a personal device opened Florida's DMV database to ShinyHunters.
• How attackers phished 347,000 Trezor users by hijacking a trusted email vendor.
• How two ransomware gangs hit Interim HealthCare and leaked the data despite the pressure.
• Why your security is only as strong as the login you handed someone else.
• What business owners should do about vendor access and stolen credentials before it's their turn.
• Why paying a ransom is a promise from a criminal, not a recovery plan.
Security Squawk is a weekly podcast and live stream for business owners and executives.
Support the show: buymeacoffee.com/securitysquawk
Subscribe | Like | Share
#SecuritySquawk #CyberSecurity #DataBreach #Trezor #Ransomware #Phishing #VendorRisk #IdentityTheft #Healthcare #BusinessRisk #ShinyHunters #MSP