Friday, September 11, 2026Verified technology journalism

Volvo-Eicher fleet platform exposed 748,000 customers and 676,000 vehicles through unauthenticated APIs

A security researcher disclosed that unauthenticated internal APIs in the My Eicher fleet management platform, operated by the Volvo-Eicher joint venture, exposed data for 748,000 customers and 676,000 commercial vehicles in India, including sensitive identity documents such as Aadhaar cards and driving licenses. The vulnerabilities enabled full account takeover via exposed OTP records and allowed real-time tracking of any vehicle in the system. The primary flaw was fixed in November 2025 after an eight-week disclosure process; full technical details were published today.

Volvo-Eicher fleet platform exposed 748,000 customers and 676,000 vehicles through unauthenticated APIs

Volvo-Eicher Fleet Platform Exposed 748,000 Customers Through Unauthenticated APIs

Cite this story

ProvenBrief (2026). "Volvo-Eicher fleet platform exposed 748,000 customers and 676,000 vehicles through unauthenticated APIs." ProvenBrief. https://provenbrief.com/story/volvo-eicher-fleet-platform-exposed-748-000-customers-and-676-000-vehicles-throu

Free to quote and link with attribution. Republishing in full or AI-training use requires a license.

Verified31 factual claims in this story were independently checked against primary sources before publication. Read our editorial standards.

Get the next brief in your inbox

One weekly email. Every claim verified against primary sources before we hit send.

Produced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.