
German auto giant Volkswagen’s subsidiary and automotive software maker Cariad leaked vast amounts of customer information after it left its Amazon cloud storage unsecured without a password, enabling anyone to access data associated with over 800,000 connected cars in Europe.
According to German news magazine Der Spiegel and Chaos Computer Club, a group of German ethical hackers who were contacted by a whistleblower, 460,000 of the 800,000 vulnerable vehicles were in Germany, the rest were purchased in other European countries, including Norway, Sweden, Netherlands, France, Belgium, Denmark, Switzerland, Austria and the UK.
Spiegel added that more than 30 affected vehicles belonged to the Hamburg police’s fleet of patrol cars and others belonged to intelligence service employees.
After being notified by the whistleblower, CCC confirmed the vulnerability on November 26 and informed Cariad about the same. The researchers gave the company 30 days to secure the unprotected cloud storage and make the data inaccessible before reporting it to the public.
Acknowledging the data security incident, Cariad said that the incident originated from poor configurations in two IT applications. The company secured the unprotected cloud storage and appreciated CCC for notifying it about the data exposure.
In a statement shared with BleepingComputer, a Cariad spokesperson said that the exposed data affected only vehicles connected to the internet and had been registered for online services.
The company added that the data was collected to “provide, develop, and improve digital functions” for its customers. “Without this data, smart, digital and personalised functions could not be provided, optimized or expanded,” the company added.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543