> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# HopCharge Analytics Export Published With Names, Phones and Coordinates
- URL: https://darkwebinformer.com/hopcharge-analytics-export-published-with-names-phones-and-coordinates/
- Published: 2026-09-03T15:38:13.000Z
- Updated: 2026-09-03T15:38:13.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report India EV Charging Published Free 

## HopCharge Analytics Export Published With Names, Phones and Coordinates

A forum actor posting as **GoreTerminal** has published what they describe as the database of **hopcharge.com**, an on demand doorstep electric vehicle charging service operating in India through mobile vans. The release is **19,323 accounts in JSON Lines format**, 114 MB uncompressed. The field list is not a customer table but a **product analytics event export**, carrying **full names, phone numbers, email addresses, IP addresses, latitude and longitude, device make, model and carrier, operating system, and per user counts for bookings made, cars added, saved locations and total money spent**. The data is released free behind a reply requirement. The claim is **unverified**.

Severity MODERATE 

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) 

Accounts19,323

Size114 MB

DistributionFree

ActorGoreTerminal

### ▣Post details

Targethopcharge.com

CountryIndia

SectorEV charging service

ListingFree, reply to unlock

Volume19,323 accounts

FormatJSON Lines, 114 MB

ObservedSep 3, 2026

ActorGoreTerminal

### !What the post claims

- 19,323 accounts
- JSON Lines format
- 114 MB uncompressed
- Analytics event export
- Full names
- Phone numbers
- Email addresses
- IP addresses
- Latitude and longitude
- City, region and country
- Device make and model
- Mobile carrier
- Operating system and version
- Application version
- Bookings made per user
- Cars added per user
- Saved locations count
- Total money spent
- Pending payment flag
- Event and upload timestamps

### ◱Screenshot

[ ![Forum post publishing an analytics export attributed to an Indian EV charging service, September 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/323798592768356967823598762396875968723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/09/323798592768356967823598762396875968723.png) 

Forum post publishing HopCharge account data, observed 3 September 2026.

### ☷Mapped techniques

The post describes no intrusion method. Both entries are inferred from the artefacts, not stated.

- Collection [T1213](https://attack.mitre.org/techniques/T1213/) Data from information repositories Inferred The field names match the export schema of a third party product analytics platform, so the source is more likely that platform's project than the company's own application database.
- Exfiltration [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration over web service Inferred Distribution runs through forum hosting behind a reply wall. The route out of the environment is not described.

### ⚠Potential impact

Analytics telemetry is more revealing than a customer table because it records **behaviour as well as identity**. For a service that drives to the customer, the **coordinates are where the vehicle was actually charged**, which in practice means a home or workplace, tied to a full name and a phone number. The per user totals for spend, bookings and vehicles added **rank the list by value**, and the device, carrier and IP fields give an attacker enough to make an account recovery or support call sound authentic.

### iStatus Unverified

The schema is **a standard analytics export rather than anything bespoke**, which points at an exposed or misconfigured analytics project rather than a compromise of the service itself, though nothing in the post addresses how it was obtained. The published sample **sits awkwardly with the headline**: it is dated 2021 and describes a user in the United States on a US carrier, which is hard to square with a service operating in India and with the claim that these are active accounts. The account is new with no standing, and Dark Web Informer has **not retrieved the file and is not linking it**. HopCharge has not publicly addressed the claim.

Want everything on this breach? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=hopcharge-2026-09-03&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=hopcharge-2026-09-03&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=hopcharge-2026-09-03&utm%5Fcontent=footer) // Threat Intelligence