Data breaches have become an unfortunate norm but the latest incident involving Volkswagen underscores just how vulnerable sensitive information can be. A German news outlet revealed that personal data and vehicle location information for more than 800,000 customers, including high-profile German figures, was freely accessible since mid-2024 due to poor security practices.
The breach originated from VW’s car app, developed by its subsidiary Cariad, which stored customer charging data on Amazon Web Services (AWS). A lack of encryption and inadequate security protocols left sensitive data—including email addresses, home addresses, and phone numbers—exposed. Shockingly, one file even contained login credentials to VW’s Amazon cloud account, granting potential access to a treasure trove of customer information.
The leak affected multiple Volkswagen Group brands, including Audi, Seat, and Skoda. For the Volkswagen and Seat models, geolocation data was accurate within 10 centimetres, while the Audi and Skoda models were traceable within a range of 10 kilometres.
Such precise location data raises serious safety concerns, especially for high-profile individuals, such as politicians. Potential risks include stalking and physical harm, illustrating the grave implications of such data falling into the wrong hands.
An anonymous whistleblower, using freely accessible software, discovered the unprotected data and alerted Chaos Computer Club (CCC), Europe’s largest hacker association. CCC subsequently informed Lower Saxony’s State Data Protection Officer, the Federal Ministry of the Interior, and other relevant authorities.
After being notified, Cariad acted swiftly to fix the vulnerabilities. However, critics argue that the company’s delayed recognition of the issue highlights a troubling oversight in its cybersecurity measures.
This breach serves as a stark reminder of the risks inherent in a hyper-connected world. While technological advancements promise convenience and efficiency, they also demand robust security measures to safeguard sensitive data. For Volkswagen and its affected brands, rebuilding trust will likely require significant improvements in data protection practices.