Love Electric Driver Database Offered for Sale After Security Breach
A threat actor claims to have stolen 877,000 records from the UK electric-vehicle broker.
A security breach at Love Electric, a UK-based electric-vehicle salary sacrifice broker, has resulted in the alleged theft of a massive driver database. The incident was first reported in August 2026, signaling a significant exposure of user data within the EV sector.
According to reports from Security Affairs and researcher Pierluigi Paganini, a threat actor operating under the name 'seraphims' claimed to have obtained a database containing 877,000 driver records. The actor subsequently offered the stolen data for sale on an English-language data-breach forum. The asking price for the dataset was set at $600, payable in cryptocurrency.
The EV Infrastructure Landscape
Love Electric operates as a broker for salary sacrifice schemes, a popular financial arrangement in the UK that allows employees to lease electric vehicles through their employers to reduce taxable income. Because these brokers handle a combination of employment details, financial agreements, and personal identification to facilitate vehicle leasing, they hold highly sensitive datasets. The rise of EV adoption has made such brokers attractive targets for cybercriminals seeking structured personal data for identity theft or targeted phishing campaigns.
Industry Implications
This breach highlights the growing vulnerability of the energy and electric-vehicle ecosystem. While not a direct attack on the power grid, the compromise of a major broker demonstrates how third-party service providers can become the weak link in critical infrastructure management. When nearly 900,000 records are leaked, the risk extends beyond the company itself to the thousands of corporate employers and individual drivers whose private information is now potentially available to malicious actors.
Remaining Questions
While the volume of data and the identity of the threat actor have been identified, the exact method of entry into Love Electric's systems remains unconfirmed. It is currently unclear whether the breach occurred via a direct system intrusion, a misconfigured database, or a compromise of a third-party vendor. Security analysts continue to monitor breach forums to determine if the dataset has been sold or leaked publicly.