decrypted · 29 august 2026 · ransomware and cybercrime · supply chain · uk policy and law

The Love Electric breach and the case for holding less data

On 26 August a seller going by "seraphims" listed 877,000 driver records from Love Electric, an Edinburgh-based broker that runs electric-vehicle salary sacrifice schemes for more than 1,500 UK employers, on an English-language data-breach forum. Price: $600 in cryptocurrency, negotiable. The listing includes National Insurance numbers, DVLA driving licence numbers, dates of birth and addresses, the sort of file that turns a subject-access-request headache into an identity-fraud one. Love Electric had not commented publicly by the time researchers at Ransomnews published their analysis on 28 August, and the full record count remains unverified. But the sample checks out, and that is the part worth taking seriously.

How you tell a real breach from a hoax

Forum listings like this are cheap to fake and expensive to ignore, so verification matters as much as the breach itself. Ransomnews tested a 999-row sample, about 0.11% of the claimed dataset, by checking whether the pieces fit together the way a real production database would: quote IDs pointing to the right primary drivers, National Insurance numbers turning up only where the application logic would generate them, DVLA licence encoding cross-checking against surnames at a 98.1% match rate. That is the equivalent of checking a handful of items from a pallet of "stolen" goods against the manufacturer's own batch codes, rather than trusting the label. It does not prove all 877,000 rows are real. It does show the sample almost certainly came from Love Electric's own systems, which is enough to treat the claim as credible, not confirmed.

The seller also claims the breach used a zero-day in a third-party system. That is an unverified claim from someone selling stolen data, worth exactly as much scepticism as it sounds.

Secure by Design: the data you don't hold can't leak

Whatever let the data out, the more interesting question for UK organisations is why a salary-sacrifice administrator was still holding National Insurance numbers and driving licence numbers for drivers whose leases may have started years earlier. Secure by Design asks not just "was this system patched" but "did this system need to hold this data at all". A broker verifying eligibility for a scheme needs to check a licence once, not retain the number indefinitely. Every field kept past its operational use is a field that costs nothing to store and everything to lose. UK organisations handling FCA-regulated financial products, or anything that touches DVLA data, should be asking their own vendors the same question this week: not just how the data is protected, but why it is still there.

Also this week

Two men charged in Australia over the TeamPCP supply-chain spree. Western Australian police arrested and charged a 21- and a 23-year-old on 26 August over a year-long campaign that compromised the Trivy scanner, the LiteLLM AI gateway, and npm packages including keyv and cacheable, reportedly touching over 1,000 organisations and 500,000 stolen credentials worldwide. London Stock Exchange Group was named among the organisations exposed when the LiteLLM compromise flowed through CI/CD pipelines. It is a rare case of a supply-chain campaign ending in handcuffs rather than a retrospective, and a reminder that credentials harvested months ago do not expire just because the package did.

The Cyber Security and Resilience Bill reaches Lords committee stage on 1 September. The bill, which brings data centres and managed service providers into UK critical infrastructure regulation for the first time and tightens incident reporting to a 24-hour initial window, gets its first line-by-line scrutiny next week. Peers are expected to revisit a "transnational repression" amendment, rejected in the Commons, that would block UK authorities sharing personal data with jurisdictions where a fair trial cannot be guaranteed. Worth watching for any UK organisation that will newly find itself in scope as a "critical supplier".

Sources

If your organisation wants a second opinion on what data it really needs to keep, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.