iaai.com - Washington DC DMV Listed by babuk2 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Washington DC DMV files were among the data posted by the babuk2 ransomware group on iaai.com, the disclosure becoming public on March 14, 2025. An undisclosed number of individuals may have had internal DMV records exposed; anyone who has interacted with the agency is advised to review their accounts and monitor for suspicious activity.
People who have dealt with vehicle registration, titles, auctions, or related services through channels linked to the Washington DC Department of Motor Vehicles and iaai.com may now face uncertainty about whether their personal or vehicle-related records were among material taken in a ransomware incident. Public reporting so far offers little clarity on scale or exact contents, yet any exposure of government-adjacent or commercial files that touch licensing, ownership, or insurance data carries lasting practical consequences for identity, privacy, and financial security.
On March 14, 2025, the organization listed as iaai.com - Washington DC DMV appeared on a leak site associated with the babuk2 ransomware group. The listing asserts that internal files were exfiltrated during a ransomware attack. The number of people affected remains unknown, and further Reported Details have not been made public.
Inside the incident
What is known comes primarily from the ransomware group's own listing. On March 14, 2025, babuk2 claimed to have listed iaai.com - Washington DC DMV after a ransomware attack in which internal files were exfiltrated. No public confirmation of the attack's success, the precise date of intrusion, the volume of data taken, or any ransom demand has been independently verified in the available record. The number of individuals potentially affected is listed as unknown. Method of initial access, duration of presence inside systems, and whether any data has been released beyond the claim of exfiltration are all undisclosed. In short, the incident is documented only at the level of a group claim of ransomware activity involving internal files; everything else remains unconfirmed.
Inside babuk2
Babuk2 is a ransomware operation that follows the double-extortion model common among contemporary groups: encrypt systems and simultaneously steal data, then threaten public release if a ransom is not paid. The original Babuk group gained notoriety in 2021 for high-profile attacks and for leaking source code after an apparent internal dispute; subsequent iterations and rebranded activity under names including babuk2 have continued to target organizations across sectors, posting victims on dedicated leak sites to increase pressure. These groups typically advertise stolen data samples or full archives once a listing appears, though the mere presence of a name on such a site does not by itself prove that data has been published or that every claim is accurate. Public knowledge of babuk2's tactics centers on opportunistic exploitation of exposed services, credential theft, and lateral movement, followed by data theft and encryption. No additional claims specific to this victim beyond the listing itself are part of the public record used here.
Who is iaai.com - Washington DC DMV?
iaai.com is the public face of Insurance Auto Auctions, a large commercial platform that handles the sale of salvage, damaged, and recovered vehicles on behalf of insurers, fleets, and government entities. The Washington DC DMV is the District of Columbia's motor-vehicle agency responsible for driver licensing, vehicle registration, titles, and related records. The combined designation "iaai.com - Washington DC DMV" indicates a relationship—likely contractual or operational—between the auction service and the local DMV, a common arrangement in which government agencies use commercial auction houses to dispose of impounded, abandoned, or total-loss vehicles. Organizations of this type routinely process sensitive personal identifiers, vehicle ownership histories, insurance claim details, and sometimes financial or contact information. A breach affecting systems that sit at the intersection of a commercial auction platform and a government motor-vehicle agency therefore raises concerns that extend beyond ordinary corporate data loss into the realm of official records that citizens rely on for legal identity and property rights.
The information in question
The only data type named in the available facts is "internal files exfiltrated in ransomware attack." No further breakdown—such as customer databases, employee records, title documents, or financial files—has been disclosed. Organizations that combine auction services with DMV functions typically hold or process names, addresses, dates of birth, driver's license numbers, vehicle identification numbers, title and registration data, insurance information, and sometimes payment or lien details. Because the exact contents of the claimed exfiltration remain unconfirmed, it is not possible to state with certainty which of these categories, if any, were taken. The public record simply asserts that internal files were removed; everything beyond that is unknown.
What's at stake
For individuals, the practical risks center on identity theft, fraudulent vehicle transactions, and misuse of personal identifiers that can be hard to reverse once they circulate. Even limited internal files can contain enough structured data to enable account takeovers, false title claims, or targeted phishing that appears to come from a trusted government or auction source. For the organization, the stakes include operational disruption, potential regulatory scrutiny under data-protection and government-contract rules, reputational damage, and the cost of investigation and remediation. Because the number of people affected is unknown and the precise data types are not confirmed, the full scope of exposure cannot yet be measured; the absence of those figures itself leaves both residents and the agencies involved in a prolonged period of uncertainty.
What to do if you're exposed
Anyone who has conducted vehicle-related business with the Washington DC DMV or through iaai.com channels should treat the possibility of exposure seriously even while details remain limited. Monitor bank and credit accounts for unexpected activity, place a free fraud alert or credit freeze with the major credit bureaus, and be alert to phishing messages that reference vehicle titles, auctions, or DMV services. Review any recent correspondence or online accounts tied to those services for signs of unauthorized access. As a practical next step, readers can run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets; doing so provides an early indication of whether personal details have begun to circulate more widely.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
aosense.com - AO Sense INC. Listed by babuk2 Ransomware GroupiDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers Listed by babuk2 Ransomware GroupAtlantic Coast Consulting Inc Listed by babuk2 Ransomware GroupThe Ticktin Law Group Listed by babuk2 Ransomware GroupLatest breaches
Publicly posted by babuk2 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.