/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sensitive data of over 800K VW Group EV customers, including GPS coordinates, was exposed on an unprotected AWS database for months before being reported

The sensitive information of VW, Audi, Seat, and Skoda EV owners was left exposed on an unprotected and misconfigured cloud storage system for months

Carscoops Thanos Pappas

Context & Ripple Effects

This adds connected-vehicle location data to a recurring Volkswagen security record: a 2021 vendor lapse affecting more than 3.3 million customers followed earlier exposure of VW-related documents through a robotics supplier. The common thread is not a single vehicle defect but control of sensitive data across third-party and cloud environments.

First-order effects

  • Owners across Volkswagen, Audi, Seat and Skoda whose data sat in the misconfigured database face exposure of sensitive account and location information; VW Group must establish the database's scope, access history and remediation status.
  • The incident puts the group’s cloud-data governance under immediate scrutiny, while AWS is identified as the hosting environment rather than as the reported source of the misconfiguration.

Second-order effects

  • Other connected-car operators and their vendors have a direct reason to review cloud storage permissions, especially where telemetry or location records are centrally accessible.
  • Repeated third-party and cloud-control lapses can raise the operational burden of demonstrating that customer data is segmented, access-controlled and auditable across brands.

Third-order effects

  • If such incidents persist, connected-car competition will increasingly include data-governance execution: automakers that can prove control across suppliers and cloud deployments may hold an advantage.
  • The pattern strengthens pressure for clearer accountability between vehicle makers, vendors and cloud operators, though this report alone does not establish what response will follow.

The trend: As vehicles generate more sensitive operational data, automakers are becoming accountable not only for vehicle security but for the security of the cloud and supplier systems that process it.

Discussion

  • @parisd @parisd on bluesky
    Data security is always an afterthought for non digital-native companies.  (This doesn't mean that it's not for the digital-native ones) [embedded post]
  • @jondeeoz Jon Dee on bluesky
    While the media was obsessing about privacy issues with Chinese cars, a real story was happening 😎  —  “Volkswagen leak exposed location data for 800,000 electric cars.”  —  www.theverge.com/2024/12/30/ 2...
  • @evacide @evacide on bluesky
    This joint investigation from Der Spiegel and CCC is one of the more interesting things to come out of CCC this year.  A whistleblower tipped them off to a vuln that exposed the location data of 800k Volkswagon, Audi, Seat, and Skoda EVs. www.theverge.com/2024/12/30/ 2...
  • @alex_avoigt Alex on x
    VW Group Collects Vehicle Movement Data The Chaos Computer Club (CCC) a well-known German Group of hackers reveals that the Volkswagen Group systematically collects movement data from hundreds of thousands of vehicles from the brands VW, Audi, Skoda, and Seat and stores it over […
  • @guydealership @guydealership on x
    [NEWS] A data leak at Volkswagen Group has sparked fresh concerns about EV privacy: Over the weekend — an anonymous whistleblower discovered that sensitive data for 800,000 EV owners across Audi, VW, Seat, and Skoda was exposed. This included GPS coordinates and battery charge
  • @nzahn42 Nicolas Zahn on x
    Every data point that gets collected can be leaked, especially as car companies are notorious for poor #DataSecurity and even worse #Privacy, see eg the study by @mozilla https://foundation.mozilla.org/ ...
  • @stakedeve Steve Kenny on x
    late entry for doxxer of the year @web3privacy “Data from several countries, including Germany, Israel, and Ukraine, was accessible. In some cases, the GPS data was precise to within 10 centimeters.”
  • @m_hoppenstedt Max Hoppenstedt on x
    A severe security breach at Volkswagen exposed private data of 800.000 vehicles and their owners, including sensitive GPS info of politicians, business leaders, and police, according to a @derspiegel investigation. Full story ⬇️ https://www.spiegel.de/... [image]
  • @om @om on x
    It's hard to be a technology company when you are not really a tech company. @VW group VW, Audi, Seat, and Skoda EV owners learned it the hard way. Their info was stored on a poorly secured Amazon cloud account for months https://www.spiegel.de/...
  • @electricfelix @electricfelix on x
    “All this information should not be publicly available. But it was. Several terabytes of data on around 800,000 electric cars were accessible in an Amazon cloud storage system for months, largely unprotected. VW, Seat, Audi and Skoda vehicles in Germany, Europe and other parts [i…
  • @lukeweston Luke Weston on x
    It's not a “security breach” that's the problem. Why the hell is a car logging and recording your GPS location and sending it up to some AWS cloud? Did car owners choose this? Did they give true consent to it? The enshittification is fundamentally the problem, not a “breach”.
  • @kyleichan Kyle Chan on x
    This is a big story and will really add fuel to concerns about Chinese EVs and data security in the US and Europe.
  • @alenapopova Alena Popova on x
    Movement data from VW, Seat, Audi, and Skoda electric cars, along with owners' contact information, were left unprotected in Amazon cloud storage. The 800,000 affected vehicle owners include politicians, police, and intelligence service employees. https://www.spiegel.de/... [imag…
  • r/technews r on reddit
    Whistleblower finds unencrypted location data for 800,000 VW EVs |  Der Spiegel and Chaos Computer Club were able to tie data to car owners and their trips.
  • r/technology r on reddit
    Volkswagen leak exposed location data for 800,000 electric cars.  The leak also included the emails, addresses, and phone numbers of drivers in some cases, Der Spiegel reports.