Skip to content

HopCharge Analytics Export Published With Names, Phones and Coordinates

Breach Report India EV Charging Published Free

HopCharge Analytics Export Published With Names, Phones and Coordinates

A forum actor posting as GoreTerminal has published what they describe as the database of hopcharge.com, an on demand doorstep electric vehicle charging service operating in India through mobile vans. The release is 19,323 accounts in JSON Lines format, 114 MB uncompressed. The field list is not a customer table but a product analytics event export, carrying full names, phone numbers, email addresses, IP addresses, latitude and longitude, device make, model and carrier, operating system, and per user counts for bookings made, cars added, saved locations and total money spent. The data is released free behind a reply requirement. The claim is unverified.

Accounts19,323
Size114 MB
DistributionFree
ActorGoreTerminal

Post details

Targethopcharge.com
CountryIndia
SectorEV charging service
ListingFree, reply to unlock
Volume19,323 accounts
FormatJSON Lines, 114 MB
Observed
ActorGoreTerminal

!What the post claims

  • 19,323 accounts
  • JSON Lines format
  • 114 MB uncompressed
  • Analytics event export
  • Full names
  • Phone numbers
  • Email addresses
  • IP addresses
  • Latitude and longitude
  • City, region and country
  • Device make and model
  • Mobile carrier
  • Operating system and version
  • Application version
  • Bookings made per user
  • Cars added per user
  • Saved locations count
  • Total money spent
  • Pending payment flag
  • Event and upload timestamps

Screenshot

Forum post publishing HopCharge account data, observed 3 September 2026.

Mapped techniques

The post describes no intrusion method. Both entries are inferred from the artefacts, not stated.

  • Collection T1213 Data from information repositories Inferred The field names match the export schema of a third party product analytics platform, so the source is more likely that platform's project than the company's own application database.
  • Exfiltration T1567 Exfiltration over web service Inferred Distribution runs through forum hosting behind a reply wall. The route out of the environment is not described.

Potential impact

Analytics telemetry is more revealing than a customer table because it records behaviour as well as identity. For a service that drives to the customer, the coordinates are where the vehicle was actually charged, which in practice means a home or workplace, tied to a full name and a phone number. The per user totals for spend, bookings and vehicles added rank the list by value, and the device, carrier and IP fields give an attacker enough to make an account recovery or support call sound authentic.

iStatus Unverified

The schema is a standard analytics export rather than anything bespoke, which points at an exposed or misconfigured analytics project rather than a compromise of the service itself, though nothing in the post addresses how it was obtained. The published sample sits awkwardly with the headline: it is dated 2021 and describes a user in the United States on a US carrier, which is hard to square with a service operating in India and with the claim that these are active accounts. The account is new with no standing, and Dark Web Informer has not retrieved the file and is not linking it. HopCharge has not publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest