A threat actor is claiming responsibility for an alleged data breach affecting BENY New Energy, a global manufacturer of solar photovoltaic safety equipment, energy storage products, and EV charging solutions.
According to a forum post published on July 24, the actor claims to have compromised BENY’s infrastructure and exfiltrated data belonging to approximately 13,600 users. At the time of publication, BENY had not issued any public statement regarding the alleged incident, and no independent confirmation of the claims has been established.
Forum post alleges customer database exposure
The threat actor claims the breach exposed a database containing user account information, including:
- User IDs
- Email addresses
- Mobile numbers
- Gender information
- Physical addresses
- Usernames
- Account status
- Hashed passwords
To support the claim, the forum post includes a screenshot that appears to show a development database alongside sample customer and administrative records. The database image displays a schema containing dozens of application tables with names referencing EV charging, battery systems, firmware, diagnostics, messaging, cryptographic functions, and other backend components.
The accompanying sample data includes what appear to be customer account records and a separate administrative user table. The administrative records shown in the post appear to use Argon2id password hashes, while the customer dataset contains shorter hexadecimal password hashes. The differing formats could indicate multiple applications or authentication systems were allegedly included in the exposed data.
Posted evidence offers additional context
Unlike many forum posts that only include isolated data samples, the evidence shared here also appears to show part of the underlying database structure. Visible table names reference charging sessions, battery management, firmware, diagnostics, communications, and other application components that would be consistent with BENY’s products and cloud platform.
That said, the screenshot and sample records alone do not independently verify the actor’s claims or establish how the information was obtained. It is not currently possible to confirm the authenticity, scope, or recency of the alleged compromise based solely on the material that was published.
Potential risks if the data is authentic
If the data is genuine, affected users could face an increased risk of phishing, credential stuffing, and targeted social engineering attacks. While the passwords shown in the samples appear to be hashed rather than stored in plaintext, compromised password hashes may still present a security risk depending on the hashing algorithm, implementation, and the strength of the original passwords.
The apparent inclusion of administrative account information could also provide additional insight into backend systems if the records are authentic, although there is no independent evidence that the actor retained ongoing administrative access.
No public confirmation from BENY
BENY continues to operate its public website and has recently announced new product certifications and company updates. No security advisory or incident notification was visible on the company’s website at the time of publication.
The actor behind the alleged BENY breach is the same individual BreachNews previously reported on in the Accenture incident, which was later confirmed by the company. While that history may provide additional context, each claim should be assessed on its own merits. Readers can find our previous coverage here. For another recent alleged database exposure, see PokemonGym.nl database allegedly leaked with 19,600 user records.












