Third‑Party Salary‑Sacrifice Provider Love Electric Exposes 877K Driver Records on Dark Web
What Happened — A seller on a breach‑forum offered 877,000 driver‑record entries from Love Electric, a UK‑based EV salary‑sacrifice administrator, for $600 in cryptocurrency. A sample of 999 rows was verified by researchers and shown to be a genuine production dataset, confirming that the breach is real.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates a classic vendor‑management failure: a third‑party processor storing payroll‑level personal data without sufficient SOC 2‑aligned controls.
- Continuous monitoring of vendor security posture and documented evidence of due‑diligence are essential to satisfy the SOC 2 CC6.1 (Vendor Management) and CC1.1 (Control Environment) criteria.
- Mapping this breach to your own vendor‑risk program helps you prove to auditors that you have identified, assessed, and mitigated third‑party exposure.
Who Is Affected — Financial‑services firms that use salary‑sacrifice platforms, their employee populations (drivers), and any downstream insurers or tax authorities that rely on the data.
Recommended Actions
- Initiate a formal third‑party risk review of the salary‑sacrifice provider, focusing on SOC 2‑type controls for data protection, access management, and incident response.
- Collect continuous evidence (audit logs, security attestations) from the vendor to demonstrate ongoing compliance.
- Update your incident‑response playbook to include data‑exfiltration scenarios involving payroll‑level data from third‑party services.
Source: SecurityAffairs
Technical Notes — The breach was disclosed via a dark‑web forum; no specific vulnerability (CVE) was identified. The exposed fields include National Insurance numbers, driving‑license details, and personal identifiers, all of which are classified as sensitive personal data under UK GDPR. Source: [SecurityAffairs]