Data leak

Volkswagen Group CARIAD EV Location Data Leak (AWS Misconfiguration)

πŸ“… 2024-01-01 🏒 Amazon Web Services (AWS) S3
Primary Source β†—

Incident Details

Volkswagen Group’s software subsidiary CARIAD left data on approximately 800,000 EV owners unencrypted and publicly accessible in AWS cloud storage for months. Affected brands: Volkswagen, Audi, SEAT, and Skoda. The exposed data included driver names, email addresses, phone numbers, home addresses, and precise vehicle location data (movement logs of when/where cars switched on and off). For 460,000+ vehicles, location data was accurate to within 10cm, enabling tracking of owners to homes, workplaces, and sensitive locations. An anonymous hacker discovered the breach and reported it to Germany’s Chaos Computer Club (CCC), which gave VW Group 30 days to remediate before public disclosure. No evidence of malicious exploitation. Volkswagen Group stated no customer action was required. Notable for the precision of location tracking exposed and the automotive/IoT sector privacy implications.

Technical Details

Initial Attack Vector
Amazon Web Services (AWS) cloud storage misconfiguration: data left unencrypted and publicly accessible in S3 buckets managed by Volkswagen's software subsidiary CARIAD
Vendor / Product
Amazon Web Services (AWS) S3

Timeline

  1. 2024-01-01 Breach occurred
  2. 2024-12-27 Publicly disclosed
  3. 2025-01-01 Customers notified