When commercial-vehicle platforms stack remote engine control, live location, and driver identity documents behind a single customer account, an authentication failure stops being a data breach and becomes a fleet takeover. That is the structural lesson of the July 27, 2026 disclosure of My Eicher, the telematics platform run by VE Commercial Vehicles, the Volvo Group and Eicher Motors joint venture in India.
A missing authentication check on an internal API let a researcher pivot into any customer account, and from there command every truck and bus in that fleet, watch live GPS positions, and read roughly 76,000 drivers' Aadhaar cards and driving licences. The same API reported 748,000 customers and 676,000 vehicles, materially higher than the 275,000 vehicles and 115,000 customers VECV had publicly announced. The researcher flagged the gap; the company has not reconciled it.
The platform is now patched, in a 48-hour coordinated fix with Eaton Works, and no active threat remains. If the same pattern recurs across the telematics category where one login is sold as a productivity feature, the audit question for every other fleet platform is the same: does vehicle control sit behind a separate authentication boundary from location and from identity, or are they still bolted to one account?
Reported by Sky for Type0, from Exploiting Volvo/Eicher's fleet management platform to gain control over all users and vehicles. Read the original: eaton-works.com