China
Energy / Connected Devices
Point-Gated Download
BENY New Energy Allegedly Breached, User Data Plus Access to EV Charging and Firmware Platforms Shown
A forum user posting as 888 has published what they describe as a breach of Beny.com, operated by BENY New Energy, a manufacturer of solar photovoltaic safety equipment, microinverters, battery storage systems, and EV charging hardware. The post claims 13,600 unique users were exposed, listing IDs, email addresses, mobile numbers, genders, addresses, usernames, account statuses, and hashed passwords. More significant than the record count is the accompanying proof-of-access material, which shows a live database client connected to an internet-reachable server hosting a dozen databases, among them EV charging management platforms, a firmware management system, and a device monitoring platform. The sample also exposes administrator accounts with root-level roles. The claim is unverified.
▣Post details
China!Allegedly included
- Email addresses
- Usernames & nicknames
- Mobile numbers
- Physical addresses
- Gender
- Argon2id password hashes
- Administrator accounts
- Role & permission data
- Organisation identifiers
- EV charging platform databases
- Charge session & order tables
- Firmware management system
- Device monitoring platform
- Certificate template tables
- Diagnostic & communication logs
- Battery & inverter device records
◱Screenshots
⚠Potential impact
Treating this as a 13,600-user data leak would miss what the post actually shows. The customer records are unremarkable by comparison, and the passwords use Argon2id, which makes bulk recovery impractical even though the parameters are lower than current best practice. The exposure that matters is infrastructural. The proof material depicts an authenticated session against a database server reachable over the internet, alongside databases whose names correspond to EV charging management built on the OCPP protocol, a firmware management system, and a device monitoring platform. Table names within them cover charge sessions and orders, device diagnostics, communication logs, certificate templates, and cryptographic material, which is the machinery governing trust between a vendor's cloud and the hardware deployed in the field. BENY's products are grid-connected and physically consequential: solar inverters, battery energy storage, and EV chargers. Where a vendor's firmware distribution and device management systems are reachable, the theoretical worst case is not data loss but manipulation of deployed hardware at scale, a scenario with documented research interest precisely because aggregated inverters and chargers interact with grid stability. It should be stated plainly that the post demonstrates database visibility and does not establish that firmware signing, device command channels, or fleet control were actually reachable, and that distinction matters. Even so, the presence of root-level administrator credentials in the sample and a directly addressable server materially raises the floor of what a competent buyer could attempt. The claim is unverified.
iStatus
UnverifiedThis listing carries stronger evidence than most: rather than a field list alone, it includes screenshots of an apparently live database session showing schema structure, alongside record samples from the user table. Dark Web Informer is not reproducing the server address visible in that material. The account is the same long-established, high-standing forum moderator behind a separate leak published the previous day, and the download sits behind a points paywall. Sample records show an international customer base spanning European, Middle Eastern, and Latin American email domains, indicating the affected population is not confined to the company's home market. The claim is unverified and BENY New Energy has not publicly addressed it. Owners of affected hardware cannot act on this directly, which places the burden on the vendor to confirm whether device management and firmware pathways were reachable.
DARK WEB INFORMER - THREAT INTELLIGENCE