Security Guides
Charging history wasn't on the list, but every record had an email — what CHAEVI users should do after the breach
Korean EV-charging platform CHAEVI says a July 23, 2026 hacking attack leaked 298,333 personal data records. From its own notices: what leaked, whether charging history or location was included, and what users should do now.
Who this is for: anyone who uses or once registered with CHAEVI (채비), a South Korean electric-vehicle charging app; EV drivers anywhere who want to know what a charging-app breach can expose; and developers and operators of small platforms that handle user data. This article is based on the notices CHAEVI posted on its own website, and it does not describe attack methods.
What users should do now
Check whether you're affected on CHAEVI's site — opened by you
CHAEVI's notice says the leaked items differ by person and can be checked on its "personal data leak lookup" page. Don't use a lookup link that arrives by email or text. Type chaevi.com into your browser yourself, or go through the CHAEVI app you already have installed. "Check if your data was leaked" is exactly the phrase a fake link would use.
Change your password, starting where you reused it
CHAEVI's July 26 notice asked users to change their password right away, and its July 30 follow-up recommended that if you use the same or a similar password on another site, you change that one too. Email and password (encrypted) leaked together in 131,411 + 829 records. The order to go in is email account → banking and payments → everything else, because whoever controls your email can reset the passwords of your other services. The realistic way to use a different password everywhere is a password manager; to protect your email account, see choosing MFA the right way.
Verify any CHAEVI email, text or call through the app or customer service
CHAEVI says it will never ask for your password, financial information or verification codes by phone, text or email. Its guidance is not to open links or attachments in texts or emails from unclear sources, and not to install apps when prompted. If a call or message claiming to be from CHAEVI or a public agency looks suspicious, don't call back the number it came from — contact CHAEVI customer service at 1522-2573 (24 hours) directly. The basics of spotting phishing are in what is phishing.
Report spam, smishing and unsolicited sales calls
CHAEVI asks users who receive unsolicited product offers (illegal telemarketing) or spam and smishing texts to report them to 118 (Korea's Personal Information Infringement Report Center) or to CHAEVI. The reporting and checking channels the Korean government recommends, and what to do if you already clicked a link, are laid out — based on the Ministry of Science and ICT's security advisory — in our article on what TVING users should do after the breach. The same steps apply here.
If you suffered harm, keep records and contact the help desks
CHAEVI's notice says no cases of secondary harm have been confirmed so far. Still, if an impersonation lost you money, or you suspect it did, keep screenshots of the emails or texts instead of deleting them, and report it to CHAEVI customer service. For remedies or advice, CHAEVI points to Korea's Personal Information Dispute Mediation Committee (1833-6972) and the Personal Information Infringement Report Center (118).
'Unpaid charging fee' and 'points expiring' are the most natural lures
EV drivers routinely get messages about charging payments, membership cards and roaming price changes. Once "CHAEVI customer" is known alongside your email address, as it now may be, emails about paying an unpaid fee, charging points expiring, reissuing a membership card or claiming breach compensation become hard to tell apart from the real thing. This site recommends one rule: for any message that asks you to pay or log in, don't judge the content — open the app yourself and see whether the same notice is there.
What happened (per CHAEVI's notices)
The following is what CHAEVI wrote in two notices on its website: "Notice and apology regarding the personal data leak incident" (July 26, 2026) and "Additional notice regarding the personal data leak" (July 30).
Around January 2025
While investigating the July incident, CHAEVI found that customer name, address, contact number and mobile number (all encrypted), data creation time and data sequence number had also been leaked around this time (July 30 follow-up). Circumstances, items and scale are under investigation with an outside specialist organization.July 23, 2026
Personal data leaked in an illegal external hacking attack. CHAEVI says it blocked the attack path as soon as it became aware.July 26
CHAEVI posts the leak and its scale (298,333 records in total) on its website, saying it has reported to the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA). Links to a leak lookup and a password-change page.Late July
Individual notices to affected customers (dated July 27 in the first notice and July 26 in the follow-up).July 30
Follow-up notice: CHAEVI says it has reported to the Personal Information Protection Commission, KISA, the Financial Services Commission, the Financial Supervisory Service and investigative authorities, and discloses the January 2025 leak.
Not in the notice's list of leaked items: charging history · station locations · vehicle info · payment data
- Total
- 298,333 records. Leaked items differ by person
- In every record
- Email address (not marked as encrypted)
- In some records
- Password (encrypted), name (encrypted), contact number (encrypted), gender, date of birth, member sequence number, sign-up date
- CHAEVI's explanation
- Information marked 'encrypted' is stored and managed with one-way encryption that cannot be decrypted, so its actual contents cannot be read from outside even if leaked
- Not leaked
- Resident registration numbers, passport numbers, and payment data such as card and account numbers. CHAEVI says it does not collect or hold these and confirmed through repeated checks that they were not leaked
- Separate (around Jan 2025)
- Customer name (encrypted), address (encrypted), contact number (encrypted), mobile number (encrypted), data creation time, data sequence number. Circumstances, items and scale under investigation
- CHAEVI's response
- Blocked the intrusion path and fixed the vulnerability; reviewed network separation and firewalls; expanded encryption; tightened access control; 24-hour monitoring; investigating the cause and preparing prevention measures with an outside specialist organization
Charging apps know when and where your car was — what about this time?
An EV-charging app can hold a different kind of data from an ordinary shopping app. Which station, what time and how much you charged adds up to a map of your daily movements. A record of charging every night at a slow charger near home is, in practice, your home location and the time you get back. So the first question in any charging-platform breach is: "was charging history included?"
On the notices' list of leaked items
- Email address (all 298,333 records)
- Password (encrypted, 132,240 records)
- Name and contact number (encrypted), gender, date of birth, member sequence number, sign-up date (2,064 records)
- January 2025 incident: address (encrypted) and more — scale under investigation
Not on the list
- Charging history, station locations, vehicle information (not listed — but not explicitly declared "not leaked")
- Resident registration and passport numbers (not collected or held — stated by CHAEVI)
- Payment data such as card and account numbers (not collected or held — stated by CHAEVI)
One distinction matters. What CHAEVI explicitly says it does not collect or hold, and therefore was not leaked, is resident registration numbers, passport numbers, and card and account numbers. The notices say nothing specific about charging history or location; those items are simply absent from the list of leaked items. Based on the notices, this site can say only this much: "charging history has not been disclosed as a leaked item." The January 2025 incident does include address (encrypted), but that is the address field in customer records, not charging locations, and its scale has not yet been disclosed. We will update this article when the investigation reports.
What "encrypted" protects against, and what it doesn't
CHAEVI says names, contact numbers and passwords were encrypted with a one-way method that cannot be decrypted, so they "cannot be used to identify individuals or to log in." In general, "one-way" means no key to reverse the value is ever created, so the kind of risk where a key leaks alongside the data and unlocks it does not exist by design. That is good design.
One-way methods still have a general limit, though. Instead of reversing a value, an attacker can run common passwords through the same method and see whether any result matches. Slow, salted methods make that comparison expensive, but a password like "1234abcd" falls first under any method. CHAEVI's notices do not name the specific method, so this site does not rate its strength. For users, the conclusion is the same either way: CHAEVI itself recommends changing your password, and email addresses were never encrypted in the first place. How hashing and salting work is explained in how to store passwords safely.
Lessons for small-platform operators
CHAEVI's first notice broke the leak into four groups by combination of items, stated what it does not collect, and linked a lookup page and a password-change page together. Letting users immediately see "which group am I in?" is a format other platforms can borrow. From here, this site distills three things operators can do before an incident.
List 'history data' and 'member data' separately, once
Data stamped with time and place — charging, trips, payments — becomes a person's movements the moment it is joined to member records. Go through your table list, mark every table that yields a place and a time when joined on member ID, and set a retention period for each. Delete history past the period you need, or break its link to the member ID. How to decide which data you shouldn't hold at all is covered in six security priorities for organizations.
Find what stays in plaintext — usually the email address
Even when names and contact numbers are protected, as here, the email address used as a login ID tends to stay in plaintext. Once it leaks, every member becomes a phishing target, so put the line you would add to a breach notice — "we never ask for your password or verification codes by email" — and your official sending domain into your everyday messages too. Settings that stop others from spoofing your sending domain are in stopping email spoofing with SPF, DKIM and DMARC.
Prepare the breach-notice template in advance
In peacetime, prepare a template with blanks for counts by leak type, items you don't collect, a lookup page, a password-change link, a 24-hour contact line and the authorities you reported to. Writing it from scratch on the day of an incident invites omissions and inconsistent wording.
This site's view: saying what was NOT included reduces anxiety
What keeps users anxious longest after a breach notice is whatever the notice didn't mention — "so what about my charging history?" CHAEVI reduced that anxiety for resident registration numbers and payment data by stating plainly that it doesn't collect them. For any service that handles location or history data, this site thinks a single separate line stating whether history data was included is the cheapest way to cut both support inquiries and secondary harm.
Sources (public record)
The facts in this article follow the public materials below. We have not speculated about undisclosed attack methods or causes.
- CHAEVI notice, "개인정보 유출 사고 관련 안내 및 사과의 말씀" (Notice and apology regarding the personal data leak incident), July 26, 2026 — chaevi.com
- CHAEVI notice, "개인정보 유출 관련 추가 안내" (Additional notice regarding the personal data leak), July 30, 2026 — chaevi.com
- News report on the notice — Boan News
- Help desks — Personal Information Dispute Mediation Committee / Personal Information Infringement Report Center
Update history
2026-09-30: First published, based on CHAEVI's July 26 notice and July 30 follow-up. We will update when results on the January 2025 leak or an announcement by Korea's Personal Information Protection Commission are published.
Read next
- Impersonation: what TVING users should do after the breach / what is phishing / smartphone security basics
- Car and mobility breaches: what Times Car members should do / what Cariteco members should do
- Passwords: password manager guide / hashing and salt
- Operators: six security priorities for organizations / SPF, DKIM and DMARC
FAQ
QWhat was leaked in the CHAEVI breach?
According to CHAEVI's July 26, 2026 notice, 298,333 records in total: 164,858 with only an email address, 131,411 with email and password (encrypted), 1,235 with email, name (encrypted), contact number (encrypted), gender, date of birth, member sequence number and sign-up date, and 829 with all of that plus the password (encrypted). What leaked differs by person, and CHAEVI says users can check whether they are affected on its 'personal data leak lookup' page.
QWas my charging history or location leaked?
The list of leaked items in CHAEVI's notice about the July 23 incident does not include charging history, charging-station locations or vehicle information. However, the notice does not explicitly say those were not leaked. What CHAEVI explicitly says it does not collect or hold, and therefore was not leaked, is resident registration numbers, passport numbers, and card and account numbers. A separately discovered leak from around January 2025 includes addresses (encrypted); its circumstances, items and scale are still under investigation.
QI drive an EV outside Korea. Does this affect me?
CHAEVI is a charging service in South Korea, so you are only in scope if you registered with its app or website. The broader lesson applies to every EV driver, though: charging apps can hold a record of where your car was and when. After any charging-app breach, check whether charging history was in scope, and treat 'unpaid charging fee' messages as suspicious by default.
QShould I change my password?
Yes. CHAEVI's July 26 notice asked users to change their password right away, and its July 30 notice recommended also changing it on any other site where you use the same or a similar password. CHAEVI says passwords were encrypted in a way that cannot be decrypted, but short or common passwords can be guessed regardless of the method, so changing it is the safe choice.
QIf it was 'encrypted', is my data safe?
CHAEVI says information marked 'encrypted' is stored with one-way encryption that cannot be decrypted, so the actual contents cannot be read from outside even if leaked. One-way means there is no key to turn the value back into the original. The notice does not name the specific method, though, and email addresses were not encrypted at all, so you still need to be on guard against phishing.
QWhat is the January 2025 leak?
According to CHAEVI's July 30 follow-up notice, while investigating the cause of the July attack it found that around January 2025 customer name (encrypted), address (encrypted), contact number (encrypted), mobile number (encrypted), data creation time and data sequence number had also been leaked. The circumstances, items and scale are being investigated with an outside specialist organization, and CHAEVI says it will notify customers separately if more is confirmed.