Love Electric Breach Exposes Up to 877,000 UK Driver Records for Sale

A seller on an English-language cybercrime forum claims to have obtained the driver database of Love Electric, a UK broker that runs electric-vehicle salary sacrifice schemes, offering approximately 877,000 driver records for $600, according to Security Affairs.

What Was Allegedly Taken

The seller, operating under the pseudonym “seraphims,” listed the database on August 26 and claims it includes sensitive personal information such as National Insurance numbers and driving license numbers, drawn from a table structured as dbo.drivers within a Microsoft SQL Server database. The seller claims the data was obtained through a zero-day vulnerability in a third-party system, though Security Affairs notes this claim remains unverified, and the actual scope and accuracy of the exposed record count has not been independently confirmed.

A Third-Party Risk Story

Love Electric operates as a broker for electric-vehicle salary sacrifice schemes, meaning the driver data it holds is typically supplied by employers on behalf of employees enrolling in the benefit — a structure that concentrates sensitive identity data (National Insurance and driving license numbers) with a third-party intermediary rather than the employer itself. If confirmed, the incident would highlight the identity-theft risk created when employee benefit administrators accumulate government identification data as a byproduct of otherwise routine benefits processing, a risk pattern security researchers have flagged repeatedly across payroll, salary-sacrifice and benefits-brokerage platforms.

Risk to Affected Drivers

Exposed National Insurance and driving license numbers are commonly used identity verification data points in the UK, meaning a confirmed breach of this scale could expose affected individuals to a heightened risk of convincing phishing attacks and identity fraud attempts that reference their real personal and vehicle information to appear legitimate. Love Electric has not yet issued a public statement confirming or denying the breach claim.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *