E-Bike Shoppers Exposed: The Fully Charged Breach Leaked 8,458 Records
HEROIC analysts uncovered the Fully Charged breach, a 2020 database leak from a UK-based e-commerce retailer specializing in electric bikes and accessories. The incident exposed 8,458 customer records containing a broad set of personally identifiable information. The data that was recieved by attackers included not just login credentials but also phone numbers, physical addresses, and IP addresses, creating a rich profile of each affected customer that goes well beyond a simple password reset situation.
How Phone Numbers, Addresses, and MD5 Hashes Enable Targeted Attacks on Fully Charged Customers
With access to full names, email addresses, phone numbers, and physical addresses from the Fully Charged database, an attacker can launch highly convincing phishing and smishing campaigns tailored to each victim. The inclusion of MD5(Salt) password hashes means credentials are also accessable to attackers with modern cracking hardware, since MD5 is considered a weak hashing algorithm by current standards. Combining cracked passwords with home addresses and phone numbers enables advanced social engineering, account takeover, and even physical threats to UK-based customers.
What Was Exposed in the Fully Charged Breach
- Email Address
- Phone Number
- Password Hash (MD5 with Salt)
- First Name
- Last Name
- IP Address
- Salt
Why the Fully Charged Breach Is a Serious Risk for UK E-Commerce Shoppers
E-commerce customers who shopped at Fully Charged before January 2020 may find their personal data is still circulating in breach trading channels today. The breadth of information exposed, from physical addresses to phone numbers, is seperate from what most credential dumps contain, making this dataset particularly useful for fraud and identity theft. UK consumers should be aware that this data could be used to bypass knowledge-based security questions at banks and utility providers, where name and address are often used for verification.
How Database Breaches Work
A database breach occurs when an unauthorized actor gains access to a platform's stored records, often by exploiting vulnerabilities in web application code, server configurations, or third-party integrations. For e-commerce platforms, the customer database typically contains a wealth of PII collected during checkout and account registration. Once extracted, this data is bundled and distributed on dark web forums and Telegram channels where it is sold or used directly by threat actors.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records, including e-commerce breaches like Fully Charged. Enter your email address to check instantly whether your personal and login data is in circulation and get clear next steps to protect your accounts.
Breach Breakdown
8,458 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds