2026 Škoda Auto — shop.skoda-auto.de e-commerce breach; customer PII + password hashes (May)
Data compromised
Names, addresses, emails, phones, order data, password hashes; financial cards described as not on affected systems
Technical writeup
Škoda Auto, the Volkswagen Group Czech marque, disclosed on 12 May 2026 (BleepingComputer) that attackers exploited an unspecified vulnerability in software powering its shop.skoda-auto.de online store, stealing personal information for an undisclosed number of customers before the flaw was patched and regulators notified. Exposed categories included names, addresses, email addresses, phone numbers, order information, and login credentials (email plus cryptographic password hashes). Škoda stated payment-card data were not stored on the compromised systems and warned shoppers about credential-reuse and phishing risk. The incident was scoped to the German e-shop channel—not broader factory or vehicle-telematics networks—and followed similar 2025 UK Renault/Dacia retail breaches cited in trade coverage.
Root cause
Exploitation of unspecified vulnerability in e-commerce portal software (shop.skoda-auto.de)