Chinese energy hardware manufacturer BENY New Energy has allegedly suffered a significant security breach that extends far beyond typical user data exposure. On July 24, 2026, threat actor 888 posted evidence of compromised access to the company’s systems, claiming exposure of approximately 13,600 user records alongside what appears to be direct database access to critical infrastructure platforms managing EV charging stations, firmware distribution, and device monitoring capabilities.
The BENY New Energy breach was discovered through screenshots depicting an authenticated database session against an internet-accessible server. The exposed data includes over 12 databases with user information such as email addresses, usernames, mobile numbers, physical addresses, gender information, and Argon2id password hashes. Administrator accounts, role and permission data, and organization identifiers were also reportedly compromised.
What Infrastructure Systems Were Potentially Compromised?
The more concerning aspect of this incident involves the infrastructural exposure rather than customer data alone. The proof material shows databases corresponding to an EV charging management system built on the OCPP protocol, a firmware management system, and a device monitoring platform. Specific exposed elements include charge session and order tables, device diagnostics, communication logs, certificate templates, and cryptographic material that governs trust between the vendor’s cloud systems and hardware deployed in the field.
BENY manufactures grid-connected products including solar inverters, battery energy storage systems, and EV chargers. Table names visible in the breach evidence cover battery and inverter device records, diagnostic and communication logs, and certificate template tables that manage device authentication and security.
How Severe Is the Security Risk?
While the user data exposure affects approximately 13,600 individuals with passwords protected by Argon2id hashing, security analysts note the passwords use parameters lower than current best practice, though bulk recovery remains impractical. The international customer base spans European, Middle Eastern, and Latin American email domains, indicating the affected population extends beyond China.
The critical concern centers on potential manipulation of deployed hardware at scale. Grid-connected inverters and chargers interact with electrical grid stability, making firmware distribution and device management system access particularly consequential. The presence of root-level administrator credentials in the sample data and a directly addressable server materially increases risk levels.
However, the posted evidence demonstrates database visibility but does not establish that firmware signing capabilities, device command channels, or fleet control systems were actually accessible. This distinction remains important for assessing the full scope of potential impact.
What Is Known About the Threat Actor?
The listing comes from actor 888, described as a long-established, high-standing forum moderator who posted a separate leak the previous day. The download sits behind a points paywall rather than being freely available. The evidence quality exceeds typical breach claims, featuring live database session screenshots with schema structure and record samples rather than simple field lists.
BENY New Energy has not publicly addressed the alleged breach. The claim remains unverified, though the strength of evidence presented is notable. Hardware owners cannot directly act on this information, placing responsibility on the vendor to confirm whether device management and firmware pathways were actually compromised.
Source: Dark Web Informer