Electric Vehicle Systems Security Incident Report
We noticed a concerning data exposure originating from Electric Vehicle Systems, a UK-based entity involved in critical motor control systems for electric vehicles. The incident, discovered on August 24, 2018, involved a significant volume of user credentials and personal identifiers. What struck us was the dual nature of the password exposure: a substantial portion of credentials were in plaintext, alongside a considerable number of MD5 hashed passwords, presenting a layered risk profile for affected individuals and the organization.
The breach at Electric Vehicle Systems appears to have originated from a compromise of their online portal, leading to the exfiltration of 29,468 records. The exposed data primarily consists of email addresses and associated credentials. Of particular concern is the presence of plaintext passwords for a significant subset of users, a critical vulnerability. Additionally, a number of password hashes, specifically in the older and less secure MD5 format, were also compromised. This dual exposure of credential types significantly amplifies the risk of account compromise, both through direct credential stuffing attacks on the compromised site and through the potential for offline cracking of the MD5 hashes. The source structure points to a database compromise, with the exfiltrated data subsequently appearing on a well-known hacking forum, indicating a clear intent for public dissemination and exploitation.
This incident from 2018 predates the widespread adoption of more robust hashing algorithms and multi-factor authentication, a common theme in breaches from that era. While specific news coverage directly linking to this particular Electric Vehicle Systems leak is scarce due to its age and the nature of the data (credential stuffing fodder rather than sensitive PII), the general threat of credential stuffing attacks stemming from such exposures remains a persistent issue. Research from organizations like the Identity Theft Resource Center consistently highlights the impact of credential stuffing as a primary vector for account takeovers, underscoring the long-term implications of such database compromises.
Breach Breakdown
29,468 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds