Skip to content

iChargePoint Dataset Claim Covers 154,944 User Accounts

Breach Report United Arab Emirates User & Device Data 154,944 Accounts

iChargePoint Dataset Claim Covers 154,944 User Accounts

A forum actor posting as GoreSpiders has released what they claim is a database belonging to iChargePoint, a portable power-bank rental company operating automated charging-station services across the United Arab Emirates. The actor states that the company was compromised through an employee account and that, after a ransom demand allegedly went unpaid, the dataset was released as a free download. The listing advertises approximately 154,944 user accounts and says the data is provided in JSON Lines format, with an uncompressed size of 1.22 GB and a compressed archive of 91 MB. Visible fields include phone numbers, IP addresses, latitude and longitude, city, country, region, carrier, device properties, operating-system details, language, platform, payment and order identifiers, permissions, user tracking flags, vending identifiers, event types, error messages and notification data. The claim is unverified.

Sponsored
Accounts154,944
Phone numbers154K+
Uncompressed1.22 GB
Compressed91 MB

Post details

TargetiChargePoint
CountryUnited Arab Emirates
SectorPower-bank rental / charging services
ListingFree database release
FormatJSON Lines
Claimed breach dateSep 18, 2026, 06:20 AM EDT
Observed
ActorGoreSpiders

!What the post claims

  • Approximately 154,944 user accounts
  • 154K+ phone numbers
  • Employee compromise as the initial access vector
  • Ransom demand allegedly went unpaid
  • Dataset released for free
  • Phone numbers
  • IP addresses
  • Latitude and longitude
  • City, country and region
  • Carrier information
  • Device properties and device-used fields
  • Language, platform and operating system
  • Payment identifiers
  • Order numbers and order IDs
  • User and verification fields
  • Geolocation and tracking permissions
  • Push-notification permissions
  • Vending identifiers
  • Event types and status fields
  • Error codes and error messages
  • Battery-level and threshold fields
  • Notification timing data
  • 1.22 GB uncompressed
  • 91 MB compressed

Screenshots

Forum post claiming an iChargePoint dataset containing user, device, location and application telemetry, observed 18 September 2026.

Mapped techniques

The actor states that an employee was compromised but does not provide enough technical detail to map the initial access method precisely. The technique below is inferred from the structured user, device and application records shown in the listing.

  • Collection T1213 Data from Information Repositories Inferred The alleged material contains structured user, device, location, payment and order-related records, which is consistent with collection from an internal application or customer-information repository.

Potential impact

If authentic, the dataset could expose users to targeted phishing, account impersonation, location-based profiling and privacy abuse. Phone numbers combined with IP addresses, city and region data, device properties and language or operating-system details could make social-engineering attempts significantly more convincing. Geolocation fields and tracking-permission data may also create a sensitive picture of how and where the service was used. Payment and order identifiers could provide further context for fraud or support impersonation.

iStatus Unverified

The forum listing provides a specific account count, file sizes, a broad field list and visible sample records. The actor also claims that an employee was compromised and that the data was released after a ransom deadline passed. However, Dark Web Informer has not independently verified the breach, the alleged employee compromise, the stated ransom narrative, the 154,944-account count or the authenticity and completeness of the released dataset.

Dark Web Informer // Threat Intelligence

Latest