Cartrack customers’ information may have been compromised in a ransomware attask on the vehicle tracking company.
In a note to customers, Cartrack says the ransomware incident happened on 26 August 2026.
The platform was secured and operational within a day, and an investigation is underway to determine the source, extent and implications of the attack.
It is believed the threat actor is a ransomware group known as “Direwolf.”
On 8 September 2026, some of the data accessed during the incident was published on the dark web.
Cartrack believes the threat actors accessed the customer database information, with business and contact information potentially compromised.
This information could include company names, physical address, and the names, email addresses and telephone numbers of nominated customer contacts.
Cartrack is warning customers that that compromised information could potentially be used to support scammers, including phishing attempts. For example, customers might receive calls, emails or SMS messages from someone pretending to represent Cartrack, their bank or another trusted organisation.
There is also a risk of invoice or payment redirection fraud, where someone claims that Cartrack’s banking details have changed.
It is encouraging customers to be cautious of unexpected communications requesting personal information, passwords, payments, other sensitive information or any change to the bank account into which you pay Cartrack.
It also suggests that customers update their Cartrack passwords