Researcher says My Eicher vehicle platform exposed customer data and let attackers take over commercial vehicle fleets

A security researcher found flaws in VE Commercial Vehicles' My Eicher platform that exposed customer, user, and vehicle data and could let someone take over accounts and manage vehicles. The reported issues included unauthenticated internal application programming interface (API) endpoints and access to sensitive documents such as Aadhaar cards. VE Commercial Vehicles, a Volvo Group and Eicher Motors joint venture, says the main flaws were fixed after disclosure and later issues were also remediated.
Why it matters: Fleet operators and drivers could have had personal data exposed and vehicle-management functions abused without logging in. Customers using the platform should watch for suspicious account activity and the vendor should verify that all related interfaces were fully locked down.

Sources

In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
SecurityWeek News 2026.07.31 100% relevant
This article is the first listed source here describing the specific My Eicher platform exposure, the affected joint venture, the attack path, and the remediation status.
← Back to all stories