Chevin Fleet Solutions declared a major outage after a cybersecurity incident disrupted its FleetWave SaaS platform, prompting the company to take Azure-hosted environments in the UK and US offline as a precaution. The disruption began on April 3 and affected customer access to fleet management services, while Chevin said it engaged external cybersecurity specialists to conduct artifact analysis, threat hunting, and deploy additional security controls before restoring service.
The company has not disclosed the root cause of the incident, the attack method, or whether any customer data was accessed or compromised. Public reporting indicates some FleetWave infrastructure in the EU and Australia remained online, suggesting the incident may have been limited to specific regions or that containment was applied in phases, while customers awaited further guidance on when the affected environments would be confirmed secure and brought back online.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Chevin indicated it would provide an update on restoration timing by April 10 after confirming the affected environment was secure. Reports also noted that some EU and Australian FleetWave infrastructure appeared to remain online during the outage.
Chevin publicly confirmed the disruption on April 3 and said it was working with external cybersecurity specialists on artifact analysis, threat hunting, and additional security controls while investigating the incident. The company did not disclose the root cause or whether customer data had been accessed.
On April 3, 2026, Chevin Fleet Solutions said it proactively took its Azure-hosted FleetWave SaaS environments in the UK and US offline as a precaution following a significant cybersecurity incident, causing a major outage for customers in those regions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.