Love Electric Breach: 877,000 Driver Records Offered for $600
What Happened – A data‑theft forum posted a dump containing 877,000 driver‑license records, vehicle IDs and personal details from Love Electric. The data were listed for sale at $600, confirming a successful exfiltration of the company’s customer database.
Why It Matters for Trust & Control Assurance –
- This incident is a textbook example of why continuous verification of data‑protection controls (access restrictions, encryption at rest, and monitoring of privileged activity) is essential for a defensible audit trail.
- It underscores the need for a privacy‑focused evidence hub that can instantly surface consent, data‑retention, and breach‑response artifacts when regulators or partners request proof.
Who Is Affected – Fleet‑management SaaS providers, transportation‑logistics firms, and any organization that stores driver‑license or vehicle‑owner data.
Recommended Actions – Map the breach to your data‑protection control objective, collect evidence of encryption, access‑review logs, and consent records, and validate that your privacy‑governance program can produce a rapid, auditable response. Source: [Security Affairs newsletter Round 592]
Technical Notes – The breach appears to have been driven by an unknown intrusion vector; no specific vulnerability or CVE was disclosed. Exfiltrated fields include name, address, driver‑license number, vehicle VIN, and phone number. Source: [Security Affairs newsletter Round 592]