[News](/news)

California DMV breached through compromised vendor

[Blog](/blog)[Breaches](/breaches)[Resources](/resources)[News](/news)

# California DMV breached through compromised vendor

##### [Edward Kost](/team/edward-kost)

February 21, 2021

The California Department of Motor Vehicles has been breached, potentially exposing millions of driver registration records.

The California DMV data was accessed through a compromised third-party vendor - Automatic Funds Transfer Services (AFTS). The DMV contractor fell victim to a ransomware attack that could expose 20 months of DMV business records.

“Automatic Funds Transfer Services, Inc. (AFTS) of Seattle was the victim of a ransomware attack in early February that may have compromised information provided to AFTS by the DMV, including the last 20 months of California vehicle registration records that contain names, addresses, license plate numbers and vehicle identification numbers (VIN).” California DMV [said in a statement](https://www.dmv.ca.gov/portal/security-breach-at-address-verification-company-may-compromise-dmv-information/).

When a vendor is breached, all of its clients could be impacted through internal pools of shared [sensitive data](https://www.upguard.com/blog/sensitive-data). The back door attack method, known as a third-party or a [supply chain attack](https://www.upguard.com/blog/supply-chain-attack),  targets vendors with poor security practices. A single breach exposes a treasure trove of sensitive data for multiple clientele. 

The pressure to quickly salvage sensitive data before clients are impacted makes third-party breaches ideal for ransomware attacks. In a [Ransomware attack](https://www.upguard.com/blog/what-is-ransomware-as-a-service) sensitive data is seized and only released if a set ransom price is paid.

But the release of seized data is never guaranteed, for this reason, the [FBI strongly discourages ransomware payments](https://www.fbi.gov/scams-and-safety/common-scams-and-crimes/ransomware#:~:text=The%20FBI%20does%20not%20support,this%20type%20of%20illegal%20activity.). Even if AFTS manages to salvage its compromised data, there’s no assurance that it hasn’t already been exfiltrated and sold on the dark web.

Organizations take a significant risk when onboarding vendors. Relinquishing sensitive data is necessary for integration, but without [upgrading security practices](https://www.upguard.com/product/vendorrisk), this inexorable effort will always introduce dangerous vulnerabilities.

## How secure is AFTS?

AFTS is a financial technology services company that provides transaction processing and payment solutions. The company offers services related to electronic fund transfers, payment processing infrastructure, and related financial technology systems for institutional clients.

* View our free preliminary report on AFTS’s security posture
* 13 risk factors, including email security, SSL, DNS health, open ports and common vulnerabilities

[View AFTS's score](/security-report/afts)

[View score](/security-report/afts)

[http://www.afts.com/](/security-report/afts)

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

## Latest news

Stay up-to-date with the latest news in cybersecurity.

[](/news/hugging-face-data-breach-2026-07-20)

#### [Hugging Face data breach: key facts and what we know so far](/news/hugging-face-data-breach-2026-07-20)

A data breach involving Hugging Face was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 20, 2026

[](/news/ey-data-breach-2026-07-19)

#### [EY data breach: what happened and what's at risk](/news/ey-data-breach-2026-07-19)

A data breach involving EY was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

#### [South Florida Injury & Convenient Care data breach exposes names and Social Security numbers](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

A data breach involving South Florida Injury & Convenient Care was reported in July 2026. See incident details, impact on customers, and security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/park-west-psychology-data-breach-2026-07-16)

#### [Park West Psychology data breach: what happened and what's at risk](/news/park-west-psychology-data-breach-2026-07-16)

A data breach involving Park West Psychology was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

#### [Fall River Municipal Credit Union data breach: what happened and what's at risk](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

A data breach involving Fall River Municipal Credit Union was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [](#)

July 14, 2026

[](/news/npcil-data-breach-2026-07-16)

#### [NPCIL data breach: World Leaks claims exposure of Kudankulam Nuclear Power Plant files](/news/npcil-data-breach-2026-07-16)

A data breach involving NPCIL was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 14, 2026

[View all news](/news)

## Protect your organization

Get in touch or book a free demo.

[Contact sales](/demo)

[Free demo](/demo)

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
