cross-posted from: https://infosec.pub/post/21710275

Volkswagen has inadvertently exposed the personal information of 800,000 electric vehicle owners, including their location data and contact details. The breach, which occurred due to a misconfiguration in the systems of Cariad, VW’s software subsidiary, left sensitive data stored on Amazon Cloud publicly accessible for months. The exposed information included precise GPS data, which allowed […] The post Volkswagen Data Breach: 800,000 Electric Car Owners’ Data Leaked appeared first on Cyber Security News.

  • kbal
    link
    fedilink
    263 months ago

    Thank you Volkswagen for providing the valuable public service of reminding everyone that letting your car have a network connection is a bad idea.

    • @tal@lemmy.today
      link
      fedilink
      English
      33 months ago

      With an EV, my guess is that the charging protocol at public charging stations probably also has the car identify itself and the charging station will record that.

      • @Rednax@lemmy.world
        link
        fedilink
        English
        43 months ago

        According to the article, precise GPS data was stolen. That is much worse than info about when and where you charged your car.

      • trollercoaster
        link
        fedilink
        English
        23 months ago
        Why on Earth would an electrical car need to identify itself to a charging station?

        Except for tracking its whereabouts?

        Don’t say for billing, because for payment on all sorts of self service vending machines, which charging stations for electrical cars pretty much are, other solutions (some with just as much tracking potential) have been existing for a long time, no need to reinvent the square wheel here.

  • @bleistift2@sopuli.xyz
    link
    fedilink
    English
    243 months ago

    Under GDPR this should incur massive fines. Let’s see how deep the German government is willing to crawl into their exhaust.

    • PonyOfWar
      link
      fedilink
      English
      163 months ago

      Data is money. Whatever data a company can legally collect (or get away with illegally collecting), they will collect.

    • federal reverseM
      link
      fedilink
      English
      113 months ago

      I don’t actually know if that’s legal anymore, because the SOS function is now required by the EU. (Also, iiuc, this breach apparently came from people who logged into the VW app to preheat their car, etc.)

    • IAmLamp
      cake
      link
      fedilink
      83 months ago

      In some cases, the SIM card isn’t difficult to locate and remove. The problem comes if these chucklefucks decided to make local systems dependent on the data connection (e.g. subscription options)

  • @tal@lemmy.today
    link
    fedilink
    English
    6
    edit-2
    3 months ago

    Additionally, 68% of the brands had experienced hacks, security incidents, or data leaks in the previous three years.

    That were detected and we know of.