Skip to content

Chevin FleetWave cybersecurity incident

Summary

Chevin Fleet Solutions logo

Chevin Fleet Solutions took affected U.S. and U.K. FleetWave environments offline after disclosing a cybersecurity incident on April 2, 2026, causing a major service outage for fleet-management customers. Missouri’s state fleet system became unavailable and required phone workarounds, while Chevin later confirmed unauthorized access to customer databases containing operational and personal information.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

Operational impacts

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Chevin Fleet Solutions experienced a confirmed unauthorized-access incident affecting its FleetWave software-as-a-service platform in April 2026. Our April 9 report documented that Chevin took affected FleetWave environments in the United States and United Kingdom offline while external specialists investigated and added security controls.

Chevin later told customers that its forensic investigation found an unauthorized third party accessed and potentially acquired data from customer databases backed up April 3. The Register’s May follow-up said the affected information varied by customer configuration and could include operational fleet data, names, contact information and payroll numbers. The evidence confirms unauthorized access but does not conclusively establish that every potentially affected record was exfiltrated.

Operational significance

FleetWave supports vehicle, driver, maintenance, compliance, inventory and logistics workflows. The Register’s initial report described a major outage across the U.S. and U.K. environments after Chevin took parts of the Azure-hosted service offline. EU and Australian infrastructure continued operating, so the documented shutdown was regional rather than a complete global loss of FleetWave. The outage created a third-party service disruption and downstream operational impact for organizations that depended on the affected environments.

Missouri provided the clearest documented U.S. customer effect. The state’s April 3 service alert said the FleetWave State Fleet Management System was unavailable because of an external vendor outage affecting the vendor’s customers. Missouri directed agencies to call staff to reserve vehicles or check reservation status while the platform was offline. A statewide Missouri service-impact overlay is therefore warranted as the jurisdiction of the affected state fleet system; it does not mean every agency, vehicle or locality across the state experienced a documented disruption.

Location assessment

Fitchburg, Massachusetts, is supported as corporate context, not as a verified incident-impact site. Chevin’s current U.S. contact page lists Chevin Fleet Solutions LLC at 881 Main St. and P.O. Box 2203 in Fitchburg, and the General Services Administration uses the same street address for the company. The U.S. Postal Service identifies 881 Main St. as the Fitchburg post office inside the Philip J. Philbin Federal Building. This supports a current mailing and contracting nexus but not a staffed headquarters.

Chevin’s Fitchburg association also has a legitimate history. A 2008 industry report documented its move to staffed offices at 76 Summer St. Later company materials used 347 Lunenburg St., but Fitchburg Planning Board records show that property was approved for automotive sales in 2024, and a dealership now lists the address. DysruptionHub therefore has high confidence that Fitchburg is a valid historical and current administrative location, but low confidence that either current street listing represents an operating Chevin office. No reviewed source reports incident-related disruption to personnel, equipment or facilities in Fitchburg.

Disclosure posture

Chevin’s public characterization evolved as its investigation progressed. Initial communications confirmed a cybersecurity incident and precautionary shutdown but did not disclose the underlying access or customer-data impact. The May customer notice reported unauthorized access and potential acquisition of customer-database information. DysruptionHub treats that sequence as an evolving forensic disclosure; the evidence does not establish that Chevin intentionally withheld a known final finding in April.

Current status

Chevin later said it had contained the incident, secured its systems and restored affected services. That affirmative recovery statement supports a resolved operational status even though the sources do not provide the exact date each FleetWave environment returned to service. The latest dated evidence of continuing April-incident impact was a SANS NewsBites report saying the affected service remained down April 10.

Confidence and uncertainty

Confidence is high that malicious cyber activity affected Chevin because the company confirmed a cybersecurity incident and later reported unauthorized third-party access to customer databases. Confidence is high that customers lost FleetWave access, and Missouri’s direct notice documents operational disruption and phone workarounds for its state fleet system.

Ransomware and extortion remain unresolved. No reviewed source identifies encryption, a ransom demand, payment, a responsible threat actor or a stable ransomware or extortion victim claim. Chevin said it took steps to prevent information from being published, sold or misused and found no evidence of the data circulating through ongoing monitoring, but those statements do not establish whether an extortion demand occurred.

Analytic gaps

The public record does not identify the initial access vector, exploited vulnerability, compromised credential or system, attacker dwell time, persistence method, malware family or command-and-control infrastructure. It also does not establish which customer tenant was first affected, how access crossed tenant or backup boundaries, or whether Microsoft Azure itself was compromised.

The number of affected organizations and individuals, the precise records accessed for each customer, confirmed exfiltration volume and notification scope remain unclear. The sources also do not identify a threat actor, confirm ransomware or extortion, disclose a ransom payment, provide the exact restoration date for each affected environment or establish physical impact at a Chevin office.

Organizations involved

Impacted locations

  • Fitchburg, Massachusetts

    Low Confidence

    Fitchburg is associated with Chevin through its historical office presence and current mailing and contracting address, but no available evidence documents incident-related disruption to personnel, facilities or equipment in Fitchburg. The location is organizational context rather than a confirmed impacted location.

Sources

U.K.-based Chevin cyber incident disrupts U.S. fleet operations

DysruptionHub reported that Chevin disclosed a cyber incident April 2 and took affected FleetWave environments in the U.S. and U.K. offline. It documented Missouri’s state fleet system as unavailable, with phone workarounds for vehicle reservations and status checks, and found no public ransomware confirmation, threat actor or group claim at that time.

Chevin Fleet Solutions Opens New Offices

Automotive Fleet reported in 2008 that Chevin moved to expanded offices at 76 Summer Street, Suite 325, in Fitchburg to support its North American customer base, training and implementation services.

Service Alert: Vendor System Outage Impacting Fleetwave

Missouri’s Office of Administration said the FleetWave State Fleet Management System was temporarily unavailable because of an external vendor outage affecting the vendor’s customers. The state directed agencies to call OA Carpool Reservations or State Vehicle and Collision Services to reserve a vehicle or check a reservation while the platform was offline.

Chevin pulls the handbrake on FleetWave software after security scare

The Register reported that Chevin confirmed a cybersecurity incident and took Azure-hosted FleetWave environments in the U.S. and U.K. offline. Chevin said it was conducting artifact analysis and threat hunting with external specialists while adding security controls; the outage left customers without the fleet platform used for vehicles, drivers, maintenance, compliance and logistics.

NewsBites Volume XXVIII – Issue 27

SANS NewsBites summarized that Chevin took FleetWave offline following an incident and that the affected service remained unavailable as of its April 10 issue. It noted disruption to U.S. and U.K. users while EU and Australian service remained available.

FleetWave outage takes another turn. Chevin confirms crooks accessed customer data

The Register reported that Chevin’s forensic investigation found an unauthorized third party accessed and potentially acquired information from customer databases backed up April 3. Potentially affected fields varied by configuration and included operational fleet data, names, contact details and payroll numbers; Chevin said impacted services were restored and the incident contained.

Missouri Office of Administration

Official profile information supporting the public description of Missouri Office of Administration.

Geographic profiles for selected U.S. locations

Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for fitchburg, cole, jefferson city, worcester.

See something that needs correction?

Signed-in members can report an error, update, or missing source.