1 reviews | Active since Apr 2022
Cartrack ransomware breach: Delayed notification and failed account access
On 14 September 2026, I received an email from Cartrack notifying me of a ransomware incident that occurred at 2am on 26 August 2026—19 days earlier.
Cartrack states that its platform was restored by 7am that morning, that it notified the relevant authorities, including the Information Regulator, on 26 August, and that it published a website notice. I acknowledge its reported containment measures, security improvements and appointment of independent cybersecurity specialists.
However, this was not simply a temporary service interruption. Cartrack’s email confirms that attackers accessed its customer database and that some information accessed during the incident was published on the dark web on 8 September 2026—six days before I received this email.
The notice states that information relating to me may include my contact details and physical address, bank-account information, and “certain vehicle and driving-related data”. Cartrack itself warns of increased risks of ****s, identity theft and impersonation.
Why did my direct notification reach me only 19 days after the incident? Although I understand that the investigation is ongoing, I expect Cartrack to explain the notification timeline, including how it aligns with its applicable data-protection obligations. Notifying authorities and publishing a website notice do not, in themselves, explain when individual customers were informed.
Immediately after receiving the email, I attempted to access my Cartrack profile and obtain assistance:
Browser login: Login unavailable. WhatsApp: No response. Mobile login: No one-time password received.
These are the difficulties I experienced on 14 September. I cannot confirm whether they were caused by the ransomware incident, and I am not claiming that all Cartrack services were unavailable. Nevertheless, Cartrack recommends changing passwords and contacting it for assistance, while my attempts to access my account and obtain help through WhatsApp were unsuccessful.
The description “certain vehicle and driving-related data” also needs clarification. Does this include historical vehicle locations, trip histories or other information revealing customers’ movements? Which of my records were accessed, and were any included in the information published on the dark web? If Cartrack cannot yet establish this, it should say so clearly and explain how it will keep me informed.
I also need confirmation of whether my vehicle-tracking and any contracted recovery services remain fully operational, whether any live-tracking access was compromised, and what practical, customer-specific assistance Cartrack will provide to address the risks identified in its own notice. Restoring a platform within five hours does not, by itself, resolve the consequences of customer information being accessed and published.
My broader dealings with Cartrack have left me with the impression that contract retention and revenue protection receive more attention than resolving customer concerns. I have experienced an approach that feels inflexible rather than supportive. This incident, combined with my unsuccessful access and support attempts, has further weakened my confidence.
I expect Cartrack to restore my account access, explain the notification delay, clarify the impact on my information and respond directly to my service and security concerns.
Customer trust is earned through reliable service, timely communication and meaningful assistance—not contractual lock-in. This experience falls well short of the dependable relationship I expect from a provider entrusted with my personal information and vehicle security.
Thank you for making us aware of this issue. Please accept our apology for the inconvenience. We will investigate and are confident that this matter will be clarified.
Kind regards
The Cartrack Team
Thank you for making us aware of this issue. Please accept our apology for the inconvenience. We will investigate and are confident that this matter will be clarified.
Kind regards
The Cartrack Team
Cartrack’s vehicle-tracking and support services require a high degree of trust, integrity and transparency. Customers entrust the company with sensitive personal information and rely on it to help protect their vehicles. These responsibilities demand more than a generic acknowledgement when something goes wrong.
In response to my HelloPeter complaint, Cartrack stated:
“Thank you for making us aware of this issue. Please accept our apology for the inconvenience. We will investigate and are confident that this matter will be clarified.”
This is not merely an inconvenience, and that response is not good enough.
Cartrack’s own email, received on 14 September 2026, confirmed that attackers had accessed its customer database during the ransomware incident on 26 August 2026, and that some information had subsequently been published on the dark web on 8 September 2026. The notice said that information relating to me may include my physical address, bank-account details and “certain vehicle and driving-related data”.
My concerns are heightened by an email impersonation attempt I have already received. The message falsely presented itself as coming from NATIS and attempted to obtain payment for what appear to be *****ulent traffic fines. The displayed sender address appeared to be associated with a Spanish lifestyle-services provider, rather than NATIS.
I am concerned that this attempt may be linked to the Cartrack data theft, although that connection has not been established. Cartrack itself warned that exposed information could be used for phishing, ****s and impersonation. Receiving precisely this type of *****ulent communication makes my request for clarity and meaningful assistance all the more urgent. I should not be left to assess my exposure without knowing which of my information was compromised.
I specifically requested clarification about what the breach means for me. Those questions remain unanswered.
Does “vehicle and driving-related data” include historical vehicle locations, trip histories or other information revealing my movements? Which of my records were accessed, and were any included in the information published on the dark web? If Cartrack cannot yet establish this, it must say so clearly and explain when and how it will update me.
Most importantly: could unauthorised third parties now access my vehicle’s live location or track its movements through compromised information, credentials or system access? Cartrack needs to distinguish clearly between the exposure of historical information and any potential access to live tracking. I am not asserting that such access is possible; I am asking a serious question that requires a direct, evidence-based answer.
Cartrack also stated that its platform was fully operational by 7am on 26 August 2026. However, when I attempted to access my account after receiving the notification on 14 September, browser login was unavailable, no mobile OTP arrived, and my WhatsApp enquiry went unanswered. Whether or not these failures were directly related to the incident, they undermined the reassurance provided. The public response does not explain these failures or address my specific access problems.
I acknowledge that Cartrack said its investigation was ongoing. However, an ongoing investigation does not remove the need to explain what is known, acknowledge what remains unknown and provide meaningful customer support. Restoring a platform does not, by itself, resolve the consequences of customer information being accessed and published.
So far, the response to my complaint has been a public acknowledgement rather than substantive answers. This leaves me with the impression that posting publicly attracts a response, but not necessarily a resolution. Customers should not have to keep raising concerns on HelloPeter to obtain meaningful assistance.
Given this loss of confidence, I request that Cartrack release me from my current contract without early-termination penalties or cancellation charges, so that I can appoint a provider in whose security, transparency and customer service I have greater confidence.
Please provide a substantive written response, a named person accountable for resolving this complaint, and a clear timeframe for confirming my contract release. My request to end the contract does not remove the need for answers about my compromised information. Any customer-specific information must be communicated to me securely and privately—not published here.
Another generic apology will not resolve this complaint. I need answers, accountable action and a clear response to my cancellation request.
Cartrack’s vehicle-tracking and support services require a high degree of trust, integrity and transparency. Customers entrust the company with sensitive personal information and rely on it to help protect their vehicles. These responsibilities demand more than a generic acknowledgement when something goes wrong.
In response to my HelloPeter complaint, Cartrack stated:
“Thank you for making us aware of this issue. Please accept our apology for the inconvenience. We will investigate and are confident that this matter will be clarified.”
This is not merely an inconvenience, and that response is not good enough.
Cartrack’s own email, received on 14 September 2026, confirmed that attackers had accessed its customer database during the ransomware incident on 26 August 2026, and that some information had subsequently been published on the dark web on 8 September 2026. The notice said that information relating to me may include my physical address, bank-account details and “certain vehicle and driving-related data”.
My concerns are heightened by an email impersonation attempt I have already received. The message falsely presented itself as coming from NATIS and attempted to obtain payment for what appear to be *****ulent traffic fines. The displayed sender address appeared to be associated with a Spanish lifestyle-services provider, rather than NATIS.
I am concerned that this attempt may be linked to the Cartrack data theft, although that connection has not been established. Cartrack itself warned that exposed information could be used for phishing, ****s and impersonation. Receiving precisely this type of *****ulent communication makes my request for clarity and meaningful assistance all the more urgent. I should not be left to assess my exposure without knowing which of my information was compromised.
I specifically requested clarification about what the breach means for me. Those questions remain unanswered.
Does “vehicle and driving-related data” include historical vehicle locations, trip histories or other information revealing my movements? Which of my records were accessed, and were any included in the information published on the dark web? If Cartrack cannot yet establish this, it must say so clearly and explain when and how it will update me.
Most importantly: could unauthorised third parties now access my vehicle’s live location or track its movements through compromised information, credentials or system access? Cartrack needs to distinguish clearly between the exposure of historical information and any potential access to live tracking. I am not asserting that such access is possible; I am asking a serious question that requires a direct, evidence-based answer.
Cartrack also stated that its platform was fully operational by 7am on 26 August 2026. However, when I attempted to access my account after receiving the notification on 14 September, browser login was unavailable, no mobile OTP arrived, and my WhatsApp enquiry went unanswered. Whether or not these failures were directly related to the incident, they undermined the reassurance provided. The public response does not explain these failures or address my specific access problems.
I acknowledge that Cartrack said its investigation was ongoing. However, an ongoing investigation does not remove the need to explain what is known, acknowledge what remains unknown and provide meaningful customer support. Restoring a platform does not, by itself, resolve the consequences of customer information being accessed and published.
So far, the response to my complaint has been a public acknowledgement rather than substantive answers. This leaves me with the impression that posting publicly attracts a response, but not necessarily a resolution. Customers should not have to keep raising concerns on HelloPeter to obtain meaningful assistance.
Given this loss of confidence, I request that Cartrack release me from my current contract without early-termination penalties or cancellation charges, so that I can appoint a provider in whose security, transparency and customer service I have greater confidence.
Please provide a substantive written response, a named person accountable for resolving this complaint, and a clear timeframe for confirming my contract release. My request to end the contract does not remove the need for answers about my compromised information. Any customer-specific information must be communicated to me securely and privately—not published here.
Another generic apology will not resolve this complaint. I need answers, accountable action and a clear response to my cancellation request.
