Menu
Browse

Cyber Incident Victim: Volkswagen

Date:

Jun 2021

Location:

United States of America

Summary

A Volkswagen Group subsidiary experienced a data breach impacting over 3 million customers and potential buyers in North America after an unauthorized party accessed unsecured records held by an external vendor. The compromised information primarily included contact details and vehicle identification numbers, with approximately 90,000 individuals—mostly Audi customers—having more sensitive data exposed such as driver's license numbers, partial account credentials, and limited Social Security numbers. The vendor had collected the marketing-related data over several years on behalf of the automaker and its dealerships. The company notified affected parties and offered credit monitoring services to those whose highly sensitive personal information was compromised.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On June 11, 2021, Volkswagen Group of America disclosed a data breach impacting approximately 3.3 million customers and prospective buyers across its Volkswagen and Audi brands in the United States and Canada. The incident involved unauthorized access to customer data managed by an undisclosed third-party vendor that provided marketing services to Volkswagen, Audi, and their dealership networks. Exposed information included basic contact details such as names, mailing addresses, email addresses, and phone numbers for the majority of affected individuals. A subset of records also contained vehicle identification numbers (VINs) associated with customer inquiries or purchases. The compromised data had been aggregated and stored by the vendor between 2014 and 2019 for marketing campaigns targeting potential and existing vehicle owners.

Cyber Incident Image

Volkswagen identified 90,000 U.S. residents—primarily linked to Audi transactions—whose highly sensitive personal information was exfiltrated, including driver's license numbers in most cases. A smaller subset of this group had additional compromised data points such as Social Security numbers, dates of birth, and account numbers associated with Audi or Volkswagen financial services. The company confirmed the breach originated from an unsecured electronic file maintained by the vendor, though no evidence suggested operational systems or dealership IT infrastructure were directly compromised. Volkswagen initiated direct notifications to severely impacted customers, offering complimentary credit monitoring services through a third-party provider. The automaker emphasized that individuals who merely inquired about vehicle purchases during the affected period were included in the breach dataset, though no evidence of misuse was confirmed at the time of disclosure. Public guidance urged vigilance against phishing attempts leveraging the exposed contact information.

Sources
Sources available to members
1 source