CyberSecurity news
@siliconangle.com
//
A significant data leak has exposed the location data of approximately 800,000 Volkswagen electric vehicles, including models from VW, Audi, Seat, and Skoda. This breach was a result of a cloud misconfiguration within Volkswagen's software subsidiary, Cariad, which stores data on Amazon Web Services. The leaked data included real-time GPS locations, with some being accurate to within ten centimeters, along with other sensitive information. The issue came to light after a whistleblower alerted the German newspaper Der Spiegel, and security researchers from the Chaos Computer Club also helped uncover the leak.
The exposed data potentially allows for the tracking of vehicle locations and could be linked to vehicle owners, their names, and contact details. This raises serious privacy concerns, and in some instances, it was possible to even determine the travel patterns of individuals, including two German politicians. The incident highlights the critical importance of robust cloud security practices by automotive manufacturers and their software subsidiaries. While Volkswagen claims accessing the data required bypassing security mechanisms, it underscores the severe consequences of mishandling sensitive customer information.
ImgSrc: d15shllkswkct0.
References :
- electrek.co: Massive data leak at Volkswagen exposes locations of 800,000 EV drivers, for months
- malware.news: Almost 800K electric cars' data exposed by Cariad
- Techzine Global: Volkswagen data breach highlights major privacy risks
- ciso2ciso.com: CISO2CISO article about exposed cloud server tracking 800,000 Volkswagen, Audi, and Skoda EVs.
- The Verge: The Verge report on Volkswagen leak exposing location data for 800,000 electric cars.
- Electrek: Electrek article about massive data leak at Volkswagen exposing locations of 800,000 EV drivers.
- www.techradar.com: TechRadar article about over 800,000 electric car owners and drivers having private info exposed online.
- Cybernews: 800,000 Volkswagen owners' data was left unprotected and exposed. What are your thoughts? Read more⤵️
- ciso2ciso.com: Exposed Cloud Server Tracks 800,000 Volkswagen, Audi, and Skoda EVs – Source:hackread.com
- arstechnica.com: whistleblower-finds-unencrypted-location-data-for-800000-vw-evs
- techcrunch.com: TechCrunch reports on a Volkswagen leak that exposed precise location data.
- www.engadget.com: Engadget reports huge Volkswagen data leak exposed the locations of 460,000 EV drivers.
- www.scworld.com: Almost 800K electric cars' data exposed by Cariad
- pxlnv.com: Volkswagen Subsidiary Left Vehicle Location Data Unprotected in Amazon Storage
- siliconangle.com: Location data from 800,000 Volkswagen vehicles exposed by cloud misconfiguration
- Pixel Envy: Volkswagen Subsidiary Left Vehicle Location Data Unprotected in Amazon Storage
- www.carscoops.com: VW Group had sensitive info, including GPS coordinates, of 800K+ electric vehicles exposed on an unprotected AWS database for months before it was alerted
- arstechnica.com: Whistleblower finds unencrypted location data for 800,000 VW EVs
- SiliconANGLE: Location data from 800,000 Volkswagen vehicles exposed by cloud misconfiguration
- techhub.social: VW Group had sensitive info, including GPS coordinates, of 800K+ electric vehicles exposed on an unprotected AWS database for months before it was alerted (Thanos Pappas/Carscoops)
- toot.majorshouse.com: Why do they need the location data in the first place? Why does any company need this data? Volkswagen leak exposed location data for 800,000 electric cars
- dataconomy.com: A data leak exposed the location data of approximately 800,000 Volkswagen (VW) electric vehicles (EVs) for several months, impacting vehicles from VW, Audi, Seat, and Skoda, as reported by Der Spiegel.
- mashable.com: Volkswagen leak exposed location of 800,000 electric car drivers for months
- tldr.nettime.org: Connected cars are great—at least until some company leaves unencrypted location data on the Internet for anyone to find.
- TechSpot: Volkswagen leak exposes private information of 800,000 EV owners, including location data
- discuss.techlore.tech: Volkswagen leak exposed location data for 800,000 electric cars
- Techlore: Volkswagen leak exposed location data for 800,000 electric cars
- indieweb.social: Cariad has since patched the vulnerability, which had revealed data about the usage of Skodas, Audis, and Seats, as well as what Motor1 calls "incredibly detailed data" for VW ID.3 and ID.4 owners. The data set also included pinpoint location data for 460,000 of the vehicles, which Der Spiegel said could be used to paint a picture of their owners' lives and daily activities
- DMR News: Volkswagen Data Leak Exposed Location Data for 800,000 Electric Cars
- osint10x.com: Exposed Cloud Server Tracks 800,000 Volkswagen, Audi, and Skoda EVs
- Osint10x: Exposed Cloud Server Tracks 800,000 Volkswagen, Audi, and Skoda EVs
- Alex Jimenez: Volkswagen leak exposed location data for 800,000 electric cars The leak also included the emails, addresses, and phone numbers of drivers in some cases, Der Spiegel reports.
Classification:
- HashTags: #DataLeak #PrivacyViolation #CloudSecurity
- Company: Volkswagen
- Target: Volkswagen EV Owners
- Product: EVs
- Feature: location tracking
- Type: DataBreach
- Severity: Major