**H1** Exposed: 877,000 Driver Records for Sale in Massive Data Breach

A staggering 877,000 driver records, including sensitive information such as National Insurance numbers and driving license numbers, have been put up for sale on a dark web forum. The records allegedly belong to Love Electric, a UK-based broker that runs electric vehicle salary sacrifice schemes. The seller, operating under the pseudonym "seraphims," claims to have obtained the data through a zero-day vulnerability in a third-party system. However, researchers from Ransomnews have raised questions about the legitimacy of the breach and the accuracy of the claimed number of records.

The sample of 999 rows, published with the listing, reveals a production-style schema, consistent relationships between records, and realistic user errors. The data includes names, email addresses, phone numbers, dates of birth, addresses, postcodes, National Insurance numbers, driving license numbers, and quote IDs. The researcher's analysis suggests that the sample is genuine, but the claimed 877,000 records remain unverified.

Love Electric Financial Services Limited, the company behind the breached records, provides EV salary sacrifice administration, credit broking, and related services to employers across the UK. The business model requires the company to collect and process sensitive information from employees, including National Insurance numbers and driving license numbers. The company's privacy policy states that it processes personal information under UK data protection law.

The seller's history on the dark web forum is less convincing, with only nine data listings published, including several scrapes rather than breaches. The "seraphims" account was created on July 22, 2026, and the Love Electric listing had attracted no replies and only 52 views when Ransomnews checked it.

The technical evidence points to a genuine production database, but the claimed number of records and the seller's alleged third-party entry point remain unverified. The price of $600 for the database, containing sensitive information, is suspiciously low, suggesting that the seller is trying to make a quick sale.

The exposure of this sensitive information creates a significant risk for the individuals affected, particularly with regards to phishing attacks. Drivers who used Love Electric should treat unexpected messages about their vehicle scheme, payroll, or tax affairs with suspicion and verify the sender through a trusted phone number or website.

The incident highlights the importance of robust security controls in supplier networks, particularly when handling high-value identity information. The seller's alleged third-party entry point is worth investigating, but it should not become the center of the story before someone verifies it.

In conclusion, the exposed driver records, including National Insurance numbers and driving license numbers, raise serious concerns about the security of Love Electric's systems and the handling of sensitive information by third-party providers. The incident serves as a reminder of the importance of robust security controls and the need for vigilance in the face of potential data breaches.

**Related Keywords:**

* Data breach * Hacking * Cybersecurity * Malware * Vulnerability * Identity theft * Phishing * Dark web * Data protection * Security research