{"success":true,"data":{"id":"ev-charging-account-takeover-credential-phish","label":"EV charging network account-takeover phish — email impersonates Tesla, ChargePoint, EVgo, Blink, IONIQ or Electrify America with a billing-failure or account-suspended hook harvesting credentials + payment card. Pwn2Own Miami 2026; FTC 2026 EV-charging complaint data.","description":"Email impersonating an EV charging network (ChargePoint, EVgo, Electrify America, Tesla Supercharger, Blink Charging, Shell Recharge) with a suspicious-login / account-sharing-violation narrative directing the recipient to verify credentials at a non-official URL. This is distinct from the existing fake-ev-charging-payment-failure-lure (which covers the payment-declined narrative): this signal covers credential takeover where attackers harvest login credentials to resell charging access, drain pre-loaded charging credits, and pivot to linked payment accounts. KrebsOnSecurity's January 2026 report documented a dark-web market for stolen ChargePoint and EVgo credentials; Malwarebytes (February 2026) and Bitdefender (January 2026) documented active credential-phishing campaigns against EV charging users. Legitimate EV charging networks rarely email users about account security; when they do, the email comes from the official vendor domain with DKIM signing.","tier":"danger","category":"phishing","isThin":false}}