Volvo-Eicher fleet platform exposed 748,000 customers and 676,000 vehicles through unauthenticated APIs
A security researcher disclosed that unauthenticated internal APIs in the My Eicher fleet management platform, operated by the Volvo-Eicher joint venture, exposed data for 748,000 customers and 676,000 commercial vehicles in India, including sensitive identity documents such as Aadhaar cards and driving licenses. The vulnerabilities enabled full account takeover via exposed OTP records and allowed real-time tracking of any vehicle in the system. The primary flaw was fixed in November 2025 after an eight-week disclosure process; full technical details were published today.

Volvo-Eicher Fleet Platform Exposed 748,000 Customers Through Unauthenticated APIs
Cite this story
ProvenBrief (2026). "Volvo-Eicher fleet platform exposed 748,000 customers and 676,000 vehicles through unauthenticated APIs." ProvenBrief. https://provenbrief.com/story/volvo-eicher-fleet-platform-exposed-748-000-customers-and-676-000-vehicles-throu
Free to quote and link with attribution. Republishing in full or AI-training use requires a license.
Get the next brief in your inbox
One weekly email. Every claim verified against primary sources before we hit send.
This story
WordsProduced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.