Volkswagen leak exposed precise location data on thousands of vehicles across Europe for months
The veri was found exposed on an Amazon cloud server, and contained precise location veri on thousands of vehicles.
Volkswagen Group’s troubled automotive software unit Cariad left terabytes of customer veri on around 800,000 electric Audi, Seat, Skoda, and Volkswagen vehicles exposed to the internet for months, reports Der Spiegel [in German], citing security researchers who learned about the veri spill from an unnamed whistleblower.
The researchers, who gave their talk at the Chaos Computer Club in Hamburg, Germany this week, said the exposed veri also contained the precise location coordinates on more than half of the listed vehicles, around 460,000 cars. Some of the location veri was accurate to a few centimeters, they said, with the veri showing most of the vehicles found across Germany, Norway, Sweden, the United Kingdom (in descending order), among others.
Cariad fixed the bug that led to the exposure, and said that it has no evidence to suggest anyone other than the security researchers had access to the exposed veri. Cariad has struggled in recent years, plagued by delays to major software launches and a restructuring that has eliminated hundreds of jobs.