Skip to main content
LiMP VPN
All news

GPS Fleet Leak Exposed 3,600 Cars to Remote Control

GPS Fleet Leak Exposed 3,600 Cars to Remote Control

In short: Researchers at Cybernews found an unprotected 136GB database belonging to the GPS fleet platform Globalfleet.eu (developed by Avigeoloc). It exposed the personal data of 131 drivers and 278 users along with live location, trip history and credentials for roughly 3,600 vehicles — and let anyone online send remote commands to lock doors or stop engines. Access was closed after a report to France's incident-response centre; no evidence of real-world abuse was found.

What happened?

On 24 June 2026 the Cybernews research team discovered a Globalfleet.eu database sitting on the open internet with no password. The platform helps small and medium rental, logistics and construction firms track and manage their vehicle fleets. Because the database was reachable by anyone, it turned a routine back-office system into a potential remote control panel for nearly 3,600 cars and trucks.

This is the same class of failure we described in our report on the robot-vacuum camera hijack: a connected device or service left exposed, letting outsiders reach data and controls that should never touch the public internet.

What exactly leaked?

The 136GB trove contained a dangerous mix of personal and operational data:

Identity data — names, addresses, phone numbers and email addresses of drivers and platform users.

Credentials — account logins with passwords stored as weak MD5-Crypt hashes, which can be cracked far more easily than modern hashing would allow.

Movement data — real-time GPS coordinates, trip history, speed, plus mobile-equipment and SIM identifiers.

Most alarming, the exposure allowed remote commands to the vehicles themselves — locking and unlocking doors and starting or stopping engines — across roughly 3,600 vehicles.

Why does this matter for ordinary users?

Even if you have never heard of Globalfleet, the incident is a textbook lesson in how much a single leaky service can reveal. Live GPS and trip history expose where people live, work and travel; leaked emails and phone numbers fuel targeted phishing; and weakly hashed passwords let attackers try the same credentials elsewhere. The ability to immobilise thousands of vehicles at once turns a data breach into a physical-safety problem.

The deeper point is that you rarely control how third parties store your data. What you can control is how much you expose yourself day to day. A no-logs VPN encrypts your traffic and hides your real IP address, which matters most on the public and vehicle Wi-Fi networks where connected fleets and drivers often connect — as explained on our features page. It cannot fix someone else's open database, but it shrinks the trail you leave and the metadata anyone can gather about you.

How can you protect your data?

Use unique, strong passwords. This breach exposed weakly hashed passwords; if you reuse one, a single leak unlocks many accounts. A password manager plus two-factor authentication contains the damage.

Limit location sharing. Review which apps and connected-car services have permanent access to your GPS, and switch them to "while using" or off.

Encrypt your connection. On public or in-vehicle Wi-Fi, a no-logs VPN such as LiMP VPN encrypts traffic and masks your IP, reducing what networks and trackers can see.

Watch for targeted phishing. After any breach, expect messages that quote real details to look legitimate. Verify independently and never enter credentials via a link you were sent.

Sources

This report is based on research by Cybernews and coverage by SecurityLab (Positive Technologies), June–July 2026.

GPS Fleet Leak Exposed 3,600 Cars to Remote Control