48 hours of live telemetry from 3,000 organisations
A threat actor using the name “laserscript” has allegedly compromised popular fleet management provider Teletrac Navman and is advertising what they claim is 48 hours of live production telemetry from almost 3,000 organisations across Australia and New Zealand.
According to reports, the dataset allegedly includes more than 670,000 GPS location records, vehicle registration details, VINs, driver contact information and, in some cases, driver licence numbers. Several government agencies, logistics providers and critical infrastructure operators have also been named as alleged victims.

The alleged dataset was advertised on a hacking forum, with prospective buyers offered a sample before purchase. Source: Daily Dark Web
Give someone 48 hours of telemetry across thousands of vehicles and they can start piecing together how an organisation operates. Regular routes, frequently visited sites, operating hours and movement between facilities all become much easier to understand.
For an attacker, that’s useful long before they ever attempt to access a network. It can help them understand how an organisation works, identify opportunities for targeted phishing, plan physical surveillance or even support cargo theft.
Attackers also don’t usually work from a single source of information. They’ll combine leaked datasets with publicly available information and previous breaches to build a much clearer picture of their target over time.
So rather than releasing the dataset publicly, they allegedly offered samples to prospective buyers before moving conversations to encrypted messaging platforms. Underground forums work much like any other marketplace. Data is advertised, buyers decide whether it’s useful, and it changes hands.
Most organisations rely on third-party platforms every day. Fleet management systems are one example, but the same applies to payroll software, HR platforms, CRM systems and cloud services. Every one of those platforms holds information about the organisation, which means a compromise affects every customer relying on that service.
From an attacker’s perspective, that’s a much more efficient way of operating. Rather than targeting hundreds or thousands of organisations individually, they only need to compromise one provider to potentially gain access to information across an entire customer base.
Every new platform an organisation uses creates another repository of business information. Over time, that information spreads across multiple providers, each holding a different piece of data that have the potential to be exposed. For many organisations, understanding supplier risk is now just as important as understanding their own environment.



