A seller on a data breach forum is offering 877,000 driver records, allegedly from UK electric vehicle salary sacrifice provider Love Electric, for $600. Researchers examined a sample of the data and found strong evidence it originated from a genuine production database, with details like National Insurance numbers and driving licence information included. However, the exact number of records and the method of acquisition remain unverified.

A data breach allegedly affecting Love Electric, a UK-based electric vehicle salary sacrifice scheme provider, has led to a threat actor offering 877,000 driver records for sale on an English-language data-breach forum. The seller, identified as "seraphims," posted the listing on August 26, offering the dataset for $600 in cryptocurrency, with the price negotiable.
While the total number of records claimed by the seller remains unverified, a sample of 999 rows published with the listing has been examined by researchers, who found strong indications that the data originated from a genuine production database. Love Electric has been contacted for comment regarding the alleged breach.
The 999-row sample, provided as a CSV file with 24 columns, appears to be an export of a `dbo.drivers` table from a Microsoft SQL Server database. The columns include `id`, `quote_id`, `user_id`, `title`, `first_name`, `last_name`, `email`, `phone_number`, `date_of_birth`, `address`, `address2`, `city`, `country`, `postcode`, `national_insurance_number`, `driving_licence_number`, `driving_licence_country`, `allow_processing_national_insurance`, `primary`, `created_at`, `updated_at`, `deleted_at`, `weekly_hours`, and `occupation_id`.
The exposed fields contain sensitive personal information such as names, email addresses, phone numbers, dates of birth, addresses, postcodes, National Insurance numbers, and driving licence numbers. The data also includes quote IDs and consent-related flags.
Analysis of the sample revealed that the data was not uniformly populated, which is consistent with real-world production data rather than synthetic datasets. For instance, approximately 71% of the rows lacked a name, address, or city, 74% had no phone number, and 85% had no National Insurance number. However, 147 records did contain a National Insurance number, and 287 included a driving licence number.
The geographical distribution of postcodes in the sample clustered around Edinburgh and central Scotland, extending into England, aligning with Love Electric's operations. Dates of birth ranged from 1946 to 1999, with a concentration among individuals born in the 1970s and 1980s.
Further validation involved testing the driving licence numbers against the structure of UK licences. Of the 108 full-length licence numbers in the sample, 98.1% had a surname block matching the surname in the corresponding record, 97.2% had an initial matching the first name, and 78.7% contained a date-of-birth encoding that matched the stored date of birth. The imperfections, such as varying licence number lengths and inconsistencies in National Insurance and phone number formats, were also noted as indicative of real user input.
The relationships between records in the sample also held up under scrutiny. The 999 rows comprised 731 primary drivers and 268 additional named drivers. There were exactly 731 distinct quote IDs, each linked to one primary driver. All 268 additional drivers referenced an existing quote within the file. The consent flag for National Insurance processing was empty for the additional drivers and populated for all primary drivers, with National Insurance numbers appearing only for primary drivers. These internal consistencies suggest the data's authenticity.
Love Electric Financial Services Limited, registered in Edinburgh under number SC374952, operates as an active Scottish company. Its business model as a salary sacrifice administrator and FCA-regulated credit broker necessitates the collection of information typically associated with payroll departments, including National Insurance numbers and driving licence details, to process schemes and manage insurance and tax requirements. The company's privacy policy states it processes personal information under UK data protection law.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed