Chevin Fleet Solutions

Chevin Fleet Solutions took affected U.S. and U.K. FleetWave environments offline after disclosing a cybersecurity incident on April 2, 2026, causing a major service outage for fleet-management customers. Missouri’s state fleet system became unavailable and required phone workarounds, while Chevin later confirmed unauthorized access to customer databases containing operational and personal information.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
A specific application or software platform became unavailable or unusable.
Business, financial, customer, administrative, or operational transactions could not be completed normally.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
DysruptionHub assesses with high confidence that Chevin Fleet Solutions experienced a confirmed unauthorized-access incident affecting its FleetWave software-as-a-service platform in April 2026. Our April 9 report documented that Chevin took affected FleetWave environments in the United States and United Kingdom offline while external specialists investigated and added security controls.
Chevin later told customers that its forensic investigation found an unauthorized third party accessed and potentially acquired data from customer databases backed up April 3. The Register’s May follow-up said the affected information varied by customer configuration and could include operational fleet data, names, contact information and payroll numbers. The evidence confirms unauthorized access but does not conclusively establish that every potentially affected record was exfiltrated.
FleetWave supports vehicle, driver, maintenance, compliance, inventory and logistics workflows. The Register’s initial report described a major outage across the U.S. and U.K. environments after Chevin took parts of the Azure-hosted service offline. EU and Australian infrastructure continued operating, so the documented shutdown was regional rather than a complete global loss of FleetWave. The outage created a third-party service disruption and downstream operational impact for organizations that depended on the affected environments.
Missouri provided the clearest documented U.S. customer effect. The state’s April 3 service alert said the FleetWave State Fleet Management System was unavailable because of an external vendor outage affecting the vendor’s customers. Missouri directed agencies to call staff to reserve vehicles or check reservation status while the platform was offline. A statewide Missouri service-impact overlay is therefore warranted as the jurisdiction of the affected state fleet system; it does not mean every agency, vehicle or locality across the state experienced a documented disruption.
Fitchburg, Massachusetts, is supported as corporate context, not as a verified incident-impact site. Chevin’s current U.S. contact page lists Chevin Fleet Solutions LLC at 881 Main St. and P.O. Box 2203 in Fitchburg, and the General Services Administration uses the same street address for the company. The U.S. Postal Service identifies 881 Main St. as the Fitchburg post office inside the Philip J. Philbin Federal Building. This supports a current mailing and contracting nexus but not a staffed headquarters.
Chevin’s Fitchburg association also has a legitimate history. A 2008 industry report documented its move to staffed offices at 76 Summer St. Later company materials used 347 Lunenburg St., but Fitchburg Planning Board records show that property was approved for automotive sales in 2024, and a dealership now lists the address. DysruptionHub therefore has high confidence that Fitchburg is a valid historical and current administrative location, but low confidence that either current street listing represents an operating Chevin office. No reviewed source reports incident-related disruption to personnel, equipment or facilities in Fitchburg.
Chevin’s public characterization evolved as its investigation progressed. Initial communications confirmed a cybersecurity incident and precautionary shutdown but did not disclose the underlying access or customer-data impact. The May customer notice reported unauthorized access and potential acquisition of customer-database information. DysruptionHub treats that sequence as an evolving forensic disclosure; the evidence does not establish that Chevin intentionally withheld a known final finding in April.
Chevin later said it had contained the incident, secured its systems and restored affected services. That affirmative recovery statement supports a resolved operational status even though the sources do not provide the exact date each FleetWave environment returned to service. The latest dated evidence of continuing April-incident impact was a SANS NewsBites report saying the affected service remained down April 10.
Confidence is high that malicious cyber activity affected Chevin because the company confirmed a cybersecurity incident and later reported unauthorized third-party access to customer databases. Confidence is high that customers lost FleetWave access, and Missouri’s direct notice documents operational disruption and phone workarounds for its state fleet system.
Ransomware and extortion remain unresolved. No reviewed source identifies encryption, a ransom demand, payment, a responsible threat actor or a stable ransomware or extortion victim claim. Chevin said it took steps to prevent information from being published, sold or misused and found no evidence of the data circulating through ongoing monitoring, but those statements do not establish whether an extortion demand occurred.
The public record does not identify the initial access vector, exploited vulnerability, compromised credential or system, attacker dwell time, persistence method, malware family or command-and-control infrastructure. It also does not establish which customer tenant was first affected, how access crossed tenant or backup boundaries, or whether Microsoft Azure itself was compromised.
The number of affected organizations and individuals, the precise records accessed for each customer, confirmed exfiltration volume and notification scope remain unclear. The sources also do not identify a threat actor, confirm ransomware or extortion, disclose a ransom payment, provide the exact restoration date for each affected environment or establish physical impact at a Chevin office.


Fitchburg is associated with Chevin through its historical office presence and current mailing and contracting address, but no available evidence documents incident-related disruption to personnel, facilities or equipment in Fitchburg. The location is organizational context rather than a confirmed impacted location.
DysruptionHub reported that Chevin disclosed a cyber incident April 2 and took affected FleetWave environments in the U.S. and U.K. offline. It documented Missouri’s state fleet system as unavailable, with phone workarounds for vehicle reservations and status checks, and found no public ransomware confirmation, threat actor or group claim at that time.
Automotive Fleet reported in 2008 that Chevin moved to expanded offices at 76 Summer Street, Suite 325, in Fitchburg to support its North American customer base, training and implementation services.
Missouri’s Office of Administration said the FleetWave State Fleet Management System was temporarily unavailable because of an external vendor outage affecting the vendor’s customers. The state directed agencies to call OA Carpool Reservations or State Vehicle and Collision Services to reserve a vehicle or check a reservation while the platform was offline.
The Register reported that Chevin confirmed a cybersecurity incident and took Azure-hosted FleetWave environments in the U.S. and U.K. offline. Chevin said it was conducting artifact analysis and threat hunting with external specialists while adding security controls; the outage left customers without the fleet platform used for vehicles, drivers, maintenance, compliance and logistics.
SANS NewsBites summarized that Chevin took FleetWave offline following an incident and that the affected service remained unavailable as of its April 10 issue. It noted disruption to U.S. and U.K. users while EU and Australian service remained available.
The Register reported that Chevin’s forensic investigation found an unauthorized third party accessed and potentially acquired information from customer databases backed up April 3. Potentially affected fields varied by configuration and included operational fleet data, names, contact details and payroll numbers; Chevin said impacted services were restored and the incident contained.
Official profile information supporting the public description of Missouri Office of Administration.
Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for fitchburg, cole, jefferson city, worcester.
Signed-in members can report an error, update, or missing source.