Volkswagen Software Unit Exposes Location Data for Nearly Half a Million Cars
Volkswagen's Cariad software division leaves precise location data for approximately 460,000 electric vehicles exposed online for months across Europe. The company states it has no evidence of malicious access beyond the security researchers who discovered the massive data spill.
A massive data leak involving Volkswagen’s software unit Cariad exposes precise location coordinates for approximately 460,000 electric vehicles across Europe. Security researchers presenting at the Chaos Computer Club reveal that terabytes of customer data from around 800,000 Audi, Seat, Skoda, and Volkswagen cars sit openly on the internet for months. An unnamed whistleblower alerts the researchers to the sprawling data spill, which primarily affects vehicles located in Germany, Norway, Sweden, and the United Kingdom.
The exposed information contains highly sensitive details, with some of the location data accurate to within a few centimeters. This unprecedented level of tracking detail creates significant privacy risks for the vehicle owners, as anyone with access to the exposed server could potentially map out the exact daily movements and routines of the drivers. The revelation highlights the vast amounts of personal information that modern connected cars collect and store as part of their standard operations.
Cariad confirms that it fixes the bug responsible for the exposure and claims there is no evidence to suggest anyone other than the security researchers accessed the vulnerable data. This incident adds to the ongoing struggles for the Volkswagen software division, which already faces severe setbacks from delayed software launches and recent restructuring efforts that eliminate hundreds of jobs. The breach raises serious questions about the data security practices within the automotive industry as vehicles become increasingly connected.