French fleet manager data leak allowed unlocking of doors, disabling vehicles
What would you do if a rental just stopped mid-travel?

Image by Cybernews.
- Globalfleet.eu exposed 136GB of customer vehicle data, including locations, driver details, and login information.
- Researchers said attackers could potentially lock doors, unlock vehicles, or stop engines on nearly 3,600 vehicles.
- The leak affected 131 drivers and 278 platform users, raising risks of phishing, tracking, and identity-based attacks.
- Vehicle tracking data included unique device identifiers, GPS coordinates, real-time location logs, and other data.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Globalfleet.eu, a GPS fleet management and tracking platform developed by Avigeoloc, leaked customer vehicle locations and personal data and enabled anyone to send remote commands, such as disabling engines and unlocking vehicle doors.
Efficiency and security is the name of the game when it comes to managing large logistics or transportation businesses. That’s why virtually all modern companies in the sector use telemetrics and real-time GPS tracking. One platform offering similar services is Globalfleet.eu.
However, on June 24th, 2026, the Cybernews research team discovered an exposed Globalfleet.eu database with 136GB of sensitive data. Everything, from vehicle drivers’ personal details to poorly protected account passwords, was exposed in the dataset.
“The data exposed a large number of vehicles to remote command execution, notably, disabling the engine and locking the doors. It also revealed bad practices, such as weak password hashing algorithms being used, and allowing command execution via database writes, in the first place,” our team explained.
Nearly 3,600 vehicles were exposed, meaning that, at least in theory, malicious actors could have stopped thousands of vehicles if they chose to, potentially causing numerous road accidents across Europe.
Our researchers could not directly contact the company, as its public email addresses appeared to be no longer working. However, the team contacted France’s CERT, and soon after, the database was secured.
The silver lining is that our team found no indications that the data was exploited. However, if our team of researchers managed to find the data, other data enthusiasts, with less noble intentions, may have done the same.
Cybernews attempted to reach out to the company for a statement, but no responsive Globalfleet.eu’s, Avigeoloc’s and related individuals’ contact information was unearthed.
What details were exposed in the Globalfleet.eu data leak?
The exposed details were on a MongoDB database, which our team identified as owned by Globalfleet.eu. Businesses often utilize MongoDB to organize and store large amounts of information. However, Globalfleet.eu’s creators are hardly the first to overlook the importance of properly configuring their databases.
According to the team, the production database contained 136GB of data, including:
- Historical vehicle locations and statuses
- Drivers’ personally identifiable information (PII)
- Operator’s PII
- Account login information
To make matters worse, the database stored user passwords protected with an MD5-Crypt hashing algorithm, which our team described as “easily crackable.”
At least in theory, with the details at hand, attackers could send remote commands to vehicles. According to the team, the commands would have allowed locking and unlocking vehicle doors, as well as starting and stopping their engines.
In total, our researchers observed information on 131 drivers, 278 platform users, and nearly 3,600 vehicles.
Moreover, every vehicle record exposed unique device identifiers (IMEI), SIM card serial numbers (ICCID), telecom subscriber identity numbers (IMSI), and phone numbers. At the same time, location logs included GPS coordinates, reverse-geocoded French street addresses, speed, satellite count, and timestamps.
The PII exposed via the publicly accessible MongoDB database contained:
- Full names
- Usernames
- Email addresses
- Hashed passwords
- Phone numbers
- Postal addresses
- IP addresses
Why is the data leak dangerous?
As always with data leaks of this nature, users whose details were exposed face increased cybersecurity risks, such as social engineering and targeted phishing attacks. These are typically utilized to trick victims into revealing additional information or to deploy malware.
Meanwhile, other leaked details enable dedicated attackers to track vehicles and know where and when they go. This type of information could be sold on the dark web to organized crime groups involved in grand theft auto.
Interestingly, our team identified multiple small- to medium-sized rental, logistics, and construction companies in the exposed dataset, which creates additional risk for individuals behind the wheel.
“People who may not have any clue about such tracking devices installed on the vehicle they are operating may be affected by an unauthorized party messing with the car’s engine and door locks.”
Disclosure timeline
- Leak discovered: June 23rd, 2026
- Initial disclosure: July 3rd, 2026
- Observed closed: July 13th, 2026
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.