July 27, 2026

Fleet Street meets fleet hack

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

A truck app glitch allegedly opened the door to whole fleets—and commenters are fuming

TLDR: A researcher says Volvo/Eicher’s fleet app exposed enough data and account access to potentially let someone take over entire truck and bus fleets. Commenters were less shocked by the bug than by what it says about modern vehicles: too much power in the cloud, not enough trust on the road.

This story landed like a high-speed pileup in the comments: a researcher says Volvo/Eicher’s My Eicher fleet platform for Indian trucks and buses was so exposed that someone could allegedly snoop customer records, pull old one-time passcodes, and even take over accounts controlling entire company fleets. We’re not talking about one driver’s dashboard here—users were gawking at the scale: hundreds of thousands of vehicles, mountains of customer data, and tens of thousands of sensitive documents like Aadhaar cards and driving licenses. For many readers, the jaw-dropper wasn’t just the bug. It was the idea that a cloud app could become the keys to the kingdom for real-world vehicles.

And the comment section absolutely went to town. One of the biggest reactions was disbelief at the response timeline: after repeated follow-ups, the issue appears to have been fixed quietly, and one commenter dryly called it a “generous timeline,” which is internet-speak for yikes. Others zoomed out into a bigger panic about modern cars themselves. One commenter basically said this is why connected vehicles are scary: if the company’s servers have a bad day, your vehicle might too. Another cut even deeper, saying there’s a difference between real protection and “security theater”—the kind that looks impressive until it matters. The jokes were dark, the mood was cynical, and the underlying vibe was clear: readers are tired of cars turning into glitchy apps on wheels.

Key Points

  • The article reports that My Eicher, operated by VE Commercial Vehicles, had unauthenticated internal/admin API exposure.
  • The write-up claims the exposed APIs allowed discovery of account data, including customer records and encrypted passwords.
  • The article describes an account takeover path using exposed OTP APIs to retrieve codes for selected mobile numbers.
  • A second takeover method was reportedly possible through password-update APIs, potentially allowing access without OTP use.
  • The reported exposure allegedly included large volumes of customer, vehicle, person, user, and identity-document data tied to Indian commercial fleets.

Hottest takes

"Quite the generous timeline" — darknavi
"You are at the complete merci of the security and correctness of the cloud management software" — spockz
"There is security that protects users and then there is security theater" — Xeoncross
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.