Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

A security researcher disclosed a major vulnerability in the 'My Eicher' fleet management platform, which exposed data for hundreds of thousands of vehicles and users in India. The flaw allowed for unauthorized access to internal APIs, potentially enabling full control over commercial fleets.
Why it matters
This highlights the critical security risks associated with the rapid digitization of industrial and commercial infrastructure, particularly in the automotive sector.
Eaton • Jul 27, 2026 Copy Link Share Key Points / Summary VE Commercial Vehicles , a joint venture between the Volvo Group and Eicher Motors, builds and maintains a fleet management system called My Eicher for Indian commercial vehicle customers. “My Eicher is a complete fleet management & vehicle GPS tracking system designed for commercial vehicle owners, fleet managers, & operators. With our highly advanced telematics platform, you can take control of your fleet like never before.” A vulnerability was found in the APIs that made it possible to discover hidden, unauthenticated internal/admin APIs. These APIs could be used to gain high-level access to systems and even enable account takeover. Account takeover made it possible to gain control over a person’s (or company’s) entire fleet, which could consist of hundreds of vehicles. Exposed data by the numbers.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in