cross-posted from: https://infosec.pub/post/21710275

Volkswagen has inadvertently exposed the personal information of 800,000 electric vehicle owners, including their location data and contact details. The breach, which occurred due to a misconfiguration in the systems of Cariad, VW’s software subsidiary, left sensitive data stored on Amazon Cloud publicly accessible for months. The exposed information included precise GPS data, which allowed […] The post Volkswagen Data Breach: 800,000 Electric Car Owners’ Data Leaked appeared first on Cyber Security News.

  • kbal
    link
    fedilink
    2623 days ago

    Thank you Volkswagen for providing the valuable public service of reminding everyone that letting your car have a network connection is a bad idea.

    • @[email protected]
      link
      fedilink
      English
      322 days ago

      With an EV, my guess is that the charging protocol at public charging stations probably also has the car identify itself and the charging station will record that.

      • @Rednax
        link
        English
        422 days ago

        According to the article, precise GPS data was stolen. That is much worse than info about when and where you charged your car.

      • trollercoaster
        link
        fedilink
        English
        221 days ago
        Why on Earth would an electrical car need to identify itself to a charging station?

        Except for tracking its whereabouts?

        Don’t say for billing, because for payment on all sorts of self service vending machines, which charging stations for electrical cars pretty much are, other solutions (some with just as much tracking potential) have been existing for a long time, no need to reinvent the square wheel here.

  • @[email protected]
    link
    fedilink
    English
    2423 days ago

    Under GDPR this should incur massive fines. Let’s see how deep the German government is willing to crawl into their exhaust.

    • PonyOfWar
      link
      fedilink
      English
      1623 days ago

      Data is money. Whatever data a company can legally collect (or get away with illegally collecting), they will collect.

  • @asbestos
    link
    English
    1223 days ago

    Are there any universal guides (like iFixit) to disable cars cellular network modules?

    • federal reverseM
      link
      fedilink
      English
      1123 days ago

      I don’t actually know if that’s legal anymore, because the SOS function is now required by the EU. (Also, iiuc, this breach apparently came from people who logged into the VW app to preheat their car, etc.)

    • IAmLamp
      link
      fedilink
      823 days ago

      In some cases, the SIM card isn’t difficult to locate and remove. The problem comes if these chucklefucks decided to make local systems dependent on the data connection (e.g. subscription options)

  • @[email protected]
    link
    fedilink
    English
    6
    edit-2
    22 days ago

    Additionally, 68% of the brands had experienced hacks, security incidents, or data leaks in the previous three years.

    That were detected and we know of.

  • @SpaceNoodle
    link
    English
    523 days ago

    CARIAD is such a clusterfuck.