Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Love Electric driver data for sale: NI, licence numbers

Ransomnews Research TeamBy Ransomnews Research TeamAugust 28, 2026Updated:August 28, 2026No Comments14 Mins Read35 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Diagram of a UK driving licence number showing surname, date of birth and initial segments, with match rates of 98.1, 78.7 and 97.2 percent against the leaked records
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

A seller on an English-language data-breach forum listed the driver database of Love Electric, a UK electric-vehicle salary sacrifice broker, on 26 August 2026, claiming 877,000 records and asking $600 in cryptocurrency. Ransomnews reviewed the 999-row sample published alongside the listing and found it consistent with a genuine production export, including National Insurance numbers and DVLA driving licence numbers. Love Electric has been contacted for comment.

// KEY FACTS

Threat actor
seraphims (data-trading forum seller)
Victim
Love Electric Financial Services Limited · Electric-vehicle salary sacrifice and leasing brokerage · United Kingdom, with drivers recorded in Scotland, England, Wales and Northern Ireland
Timeline
Attack: Not established. The seller claims August 2026 via a zero-day in a third-party system. Every row in the sample carries a created_at timestamp inside a six-second window on 2022-08-14, which is a migration artefact rather than a signup date  ·  Disclosed: 2026-08-26
Data claimed
Seller claims 877,000 records. Ransomnews reviewed the published 999-row sample, which is 0.11% of the claim · Titles, first and last names, email addresses, phone numbers, dates of birth, street addresses, cities, postcodes, home nation, National Insurance numbers, DVLA driving licence numbers, licence country, quote IDs and consent flags
Ransom status
No ransom demand. Offered for sale at $600, negotiable, any cryptocurrency
Verification
Sample reviewed by Ransomnews. Relational integrity, DVLA licence-number encoding, employer email domains, postcode geography and schema design are all consistent with a genuine production export. The 877,000-record claim is unverified and Love Electric has not commented

Who is Love Electric?

Love Electric Financial Services Limited is an Edinburgh-based broker that runs electric-vehicle salary sacrifice schemes for UK employers. Employees lease an EV through their employer’s payroll, giving up part of their gross salary in exchange, which cuts their income tax and National Insurance contributions. The company is registered in Scotland under number SC374952 at 5 South Charlotte Street, Edinburgh, is authorised and regulated by the Financial Conduct Authority under reference 743264, and is registered with the Information Commissioner’s Office under ZB075747.

The business model matters here, because it explains why a vehicle leasing broker holds the kind of data usually associated with a payroll provider. To process a salary sacrifice arrangement the broker needs to identify the employee to HMRC and to insure the driver, which means a National Insurance number and a driving licence number. Love Electric’s own privacy policy confirms it collects both, along with driving conviction history, salary information and bank details. The fields advertised in the listing match that description closely.

What is in the sample?

Ransomnews evidence panel showing the forum listing offering 877,000 Love Electric driver records for $600, with the sample download location and seller contact handle redacted
The listing as published on 26 August 2026. Ransomnews has removed the sample download location and the seller’s contact handle. The field list, price and claimed record count are unaltered.

The seller published a free sample as a 999-row CSV with 24 columns, named in a way that indicates an export of a dbo.drivers table from a Microsoft SQL Server database. The columns are: id, quote_id, user_id, title, first_name, last_name, email, phone_number, date_of_birth, address, address2, city, country, postcode, national_insurance_number, driving_licence_number, driving_licence_country, allow_processing_national_insurance, primary, created_at, updated_at, deleted_at, weekly_hours and occupation_id.

Population is uneven across the columns. Every row has a date of birth, a postcode and a home nation. Around 71% of rows have no name, address or city, 74% have no phone number and 85% have no National Insurance number. In the sample, 147 records carry a National Insurance number and 287 carry a driving licence number. Postcodes cluster heavily in Edinburgh and central Scotland, with a long tail across England. Dates of birth run from 1946 to 1999 and peak in the 1980s and 1970s, which is the age curve you would expect of employed drivers on a workplace benefit.

Three of the fields the listing advertises, weekly hours, occupation information and user ID, are empty throughout the sample, as is the soft-delete column. We cannot say whether they are populated elsewhere in the full set.

Ransomnews evidence panel showing ten rows of the leaked driver table with names, emails, dates of birth, postcodes, National Insurance numbers and driving licence numbers masked field by field
Ten rows from the sample, masked field by field so the structure is visible and no individual is identifiable. Employer email domains are removed entirely. Rows 6 to 10 are the same driver recorded five times against five different quote IDs, which is why the record count and the headcount are not the same number.

How we checked whether the sample is real

Fabricated database listings are common, and we test every sample we are sent before writing about it. Fabricated sets tend to give themselves away by being too tidy. Every field populated, every identifier well formed, and relationships between records that fall apart the moment you check them. This sample was not like that.

Relational integrity. The 999 rows split into 731 primary drivers and 268 additional named drivers. There are exactly 731 distinct quote IDs, and every quote has exactly one primary driver, 731 out of 731. All 268 additional drivers reference a quote that exists in the file, with no orphans. The consent flag governing National Insurance processing is empty for precisely the 268 additional drivers and populated for every one of the 731 primary drivers. National Insurance numbers appear on primary drivers only. Those are constraints enforced by whatever application wrote the data, and they hold across all 999 rows without exception.

DVLA licence-number encoding. A UK driving licence number is not random. Characters one to five are the holder’s surname padded with the digit 9, characters six to eleven encode the date of birth with 50 added to the month for female holders, and character twelve is the first-name initial. Of the 108 full-length licence numbers in the sample, 98.1% have a surname block matching the record’s own surname field and 97.2% have an initial matching the first-name field. 78.7% carry an encoded date of birth matching the date_of_birth column. The roughly one in five that disagree are consistent with people mistyping a sixteen-character string into a web form, which is exactly the error rate real self-reported data carries and synthetic data does not.

Abandoned and malformed input. Driving licence numbers in the sample appear at lengths of 3, 4, 6, 7, 8, 9, 11, 12, 13, 15, 16, 18, 19 and 20 characters. Only 53% of the National Insurance numbers present are valid HMRC format, with entries of four and five characters and suffixes outside the permitted A to D range. Phone numbers arrive in three inconsistent formats. That is what a live quote form leaves behind when people start typing and give up partway through.

Email domains. The sample is not consumer webmail. Alongside a minority of Gmail addresses, the bulk of email addresses sit on corporate domains belonging to identifiable UK employers, on Love Electric’s own domain, and on the domain of a European software development consultancy. That distribution is precisely what a workplace benefits platform’s database should look like, since drivers enrol through their employer. We are not naming the employer organisations, whose staff are the people actually exposed here.

Schema design. The table carries a soft-delete column, integer foreign keys to quotes and occupations rather than human-readable labels, and stores the home nation as Scotland, England, Wales or Northern Ireland rather than as a single country value. Record ID 1 is a Jane Doe test entry left behind by whoever set the table up. All of it is ordinary for software that has been in production for a few years.

For contrast, we applied the same battery this month to a listing claiming 34 million Hinge dating records and concluded it was synthetic, partly because one phrase turned up four times across profile answers supposedly written by different people. We ran the same checks here and got the opposite answer.

Who is selling it?

The account behind the listing, “seraphims”, registered on the forum on 22 July 2026, five weeks before posting this data. It has 22 posts, 11 hours of recorded time on the site, and nine threads, every one of them a data listing. Those nine went up between 27 July and 26 August, which is a rate of roughly two a week.

Ransomnews evidence panel showing nine data listings by the same seller between July and August 2026, with other alleged victim names redacted
The seller’s nine threads. We have redacted the other organisations named, because we have not examined those data sets and will not repeat unverified claims about companies we have not contacted. Reply and view counts are unaltered.

Two things in that history are worth weighing. Several of the other listings are tagged by the seller as scrapes rather than breaches, which is a different activity with a different evidential standard. And the Love Electric thread has drawn the least attention of the nine, with no replies and 52 views at the time of writing. Whatever else is true, the market has not rushed to validate it.

The account’s reputation score of 30 comes from a single positive vote, left on 17 August by a long-standing member and reading, in full, “keep scrapping”.

Ransomnews evidence panel showing a forum reputation score of 30 from a single positive vote left on 17 August 2026 with the comment keep scrapping
The seller’s entire reputation, from one vote nine days before this listing. The comment praises scraping, not breach data.

None of that tells us the Love Electric data is fake, and our examination of the sample says it is not. It does mean the seller’s standing on the forum rests on scraping work rather than on a record of selling verified breach data, and buyers on that forum would read it the same way.

Why the 877,000 figure needs care

We have seen 0.11% of what the seller claims to hold, so the headline number is unverified, and there are two specific reasons to treat it cautiously even if the seller is acting in good faith.

First, rows are not people. In the sample, 999 driver rows correspond to 731 quotes and only 58 distinct surname and date-of-birth combinations, with one individual appearing 48 times. Quote-driven tables accumulate a new driver row every time someone reconfigures a lease. If that ratio holds across the full set, the number of distinct individuals could be an order of magnitude below 877,000.

Second, the sample filename is prefixed db2_, which suggests it is one database among several in a larger dump. The 877,000 figure may describe the whole haul rather than this table.

One further detail cuts against the seller’s own timeline. Every row in the sample carries a creation timestamp inside a six-second window on 14 August 2022, between 22:54:51 and 22:54:56 UTC. That is the signature of a bulk migration into the current platform, not of genuine signup times, which means this block of records is probably legacy data carried across from an earlier system. It tells us nothing about when the data was taken, though it does suggest whoever took it reached back into legacy records rather than only recent signups.

What Love Electric drivers should do now

If you have requested a quote from or leased a vehicle through Love Electric, treat your National Insurance number and driving licence number as compromised until the company says otherwise. Neither can be changed, which is what makes this category of breach worse than a password leak.

  • Expect targeted phishing. An attacker holding your name, date of birth, address, employer and National Insurance number can write a convincing message from HMRC, your payroll department or your leasing provider. Treat any unexpected contact referencing your car scheme as hostile until verified through a number you looked up yourself.
  • Register a CIFAS protective marking. The UK fraud prevention service offers protective registration, which requires lenders to run additional checks on applications made in your name. It costs a small annual fee and is the most direct countermeasure to identity fraud using a leaked National Insurance number.
  • Check your credit file. Look for applications you did not make, across more than one bureau.
  • Do not share your driving licence number casually. It can be used with the DVLA check service to pull your licence status and endorsements.
  • Check whether your credentials are circulating separately. Our stealer-log lookup covers infostealer captures, which are a different exposure route from this one but frequently affect the same people.

Employers running a Love Electric scheme should assume their participating staff are affected, and should ask the broker directly rather than waiting, since the drivers in this data enrolled through them.

What this means for salary sacrifice schemes

The thing worth taking from this is where identity data now ends up. A vehicle leasing broker is not an organisation most people would think of as holding their National Insurance number, and it is not regulated or resourced like a payroll provider or a bank. The salary sacrifice model puts tax-grade identity data into a category of intermediary that has grown quickly on the back of the EV transition, often with lean engineering teams and a heavy dependence on third-party systems.

That dependence is the seller’s own claimed entry route, a zero-day in a third-party system, and it is a claim worth weighing sceptically. Sellers routinely inflate their access story, and third-party compromise is a convenient explanation because it is hard to disprove. We have not verified it. What we can say is that supplier compromise has become the dominant path into mid-sized companies, a pattern visible across the initial-access-broker market and in the victim feeds we maintain on the Ransomtracker.

Then there is the price. $600 for a set carrying National Insurance and driving licence numbers is not an auction reserve. It is a figure set to move the file quickly to several buyers at once, and for the people inside it that is the worse outcome of the two.

What we did not do

We did not access, probe or authenticate against any Love Electric system, and we did not purchase the full data set. Our analysis covers the free sample only. We did not validate any National Insurance number, driving licence number, email address or telephone number against any live service, and we are not publishing the sample, its download location, any individual’s details, or the names of the employer organisations whose staff appear in it. We notified Love Electric before publication and offered to share the listing and the sample with their incident response team at no cost.

Frequently asked questions

Has Love Electric confirmed a data breach?

No. Love Electric had not commented publicly at the time of publication. Ransomnews contacted the company before publishing and will update this article with any response.

Is the leaked Love Electric data real?

The published sample is consistent with a genuine production database export on every test we applied, including relational integrity, DVLA licence-number encoding and employer email domains. The seller’s claim of 877,000 records is separate and remains unverified.

What data was exposed in the Love Electric listing?

The listing advertises names, email addresses, phone numbers, dates of birth, street addresses, postcodes, National Insurance numbers, driving licence numbers, quote IDs, occupation information and weekly hours. The sample confirms most of these fields, though occupation and weekly hours are empty in it.

Why is a leaked National Insurance number serious?

A National Insurance number is a permanent identifier that cannot be reissued in the way a password or card number can. Combined with a name, date of birth and address, it supports credit applications, benefit fraud and employment fraud in the victim’s name.

How many people are actually affected?

Unknown, and probably fewer than 877,000. In the sample, 999 rows represented only 58 distinct people, because the table records one row per driver per quote and people request multiple quotes.

What should I do if I used Love Electric?

Treat your National Insurance and driving licence numbers as exposed, consider a CIFAS protective registration, monitor your credit file, and be sceptical of any unexpected message referencing your car scheme, HMRC or your payroll.

Does Love Electric have to report this?

If the data is confirmed as theirs, UK GDPR Article 33 requires notification to the Information Commissioner’s Office within 72 hours of becoming aware. As an FCA-authorised firm, Love Electric may also have an obligation to notify the regulator of a material operational incident.

Sources and further reading

  • Forum listing published 26 August 2026 by the handle “seraphims”. Ransomnews does not link to data-trading listings or to sample downloads containing personal data.
  • Love Electric Financial Services Limited company and regulatory details: loveelectric.cars important information
  • Love Electric privacy policy, confirming collection of National Insurance and driving licence numbers: loveelectric.cars privacy policy
  • Information Commissioner’s Office guidance on personal data breach reporting: ico.org.uk
  • CIFAS protective registration: cifas.org.uk
  • Related Ransomnews reporting on verifying seller claims: the McDonald’s employee data listing and the Stripe merchant API key dump
  • More about the researchers behind this analysis: Ransomnews editorial team

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleBashe interview: a ransomware group on why it wants the coverage
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Live Stripe keys for 659 merchants, published for free

August 18, 2026

Verified.ru: inside the archive of a cybercrime bureaucracy

August 17, 2026

McDonald’s employee data listed for sale in wider Entra campaign

August 16, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,459 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.