A major data breach recently affected the Volkswagen Group, exposing the private data of about 800,000 owners of electric vehicles (EVs).
A major data breach recently affected the Volkswagen Group, exposing the private data of about 800,000 owners of electric vehicles (EVs). Customers of various Volkswagen-owned brands, including Audi, Seat, Skoda, and Volkswagen itself, were affected by the hack.
Misconfigured Cloud Storage to Blame
A poorly constructed Amazon cloud storage system run by Volkswagen's software company Cariad was the cause of the hack, which was initially revealed by the German newspaper Spiegel. Vehicle and personal information were left available online for months, leaving it open to unwanted access. After discovering the vulnerability, an anonymous hacker informed the Chaos Computer Club, a well-known ethical hacking organization in Europe, about the problem.
Detailed car position data, vehicle usage timestamps, impacted consumers' home addresses, phone numbers, and email addresses were among the leaked data. Although most of the leaked data came from Germany, investigators also found data connected to cars in the UK, France, Norway, Sweden, Belgium, Denmark, and the Netherlands. Among those affected were prominent figures, including the Hamburg police and German politicians.
Swift Action Taken to Contain the Breach
Cariad, the software subsidiary in charge of overseeing the hacked Amazon cloud storage, took prompt action to secure the system. On the same day that the problem was notified, access to the exposed data was stopped.
Although the prompt action stopped more unwanted access, it is still unclear how the configuration error was overlooked for such a long time. According to Volkswagen, it is examining its cloud storage procedures to make sure that similar vulnerabilities don't arise in the future. To protect consumer data, the event has brought to light the vital significance of frequent security assessments and strict monitoring procedures.
Want your digital assets to be protected?
CyberShelter provides innovative and modern cybersecurity products and niche services to individuals and organization against all kinds of cyber threats.
For the latest cyber threats and the latest hacking news please follow us on Facebook, Linkedin, and Twitter.