2021 Volkswagen Group of America / Audi — vendor left sales & marketing datastore internet-exposed; 3.3M individuals (US/CA)
Data compromised
Names, postal/email addresses, phones, vehicle inquiry metadata; subpopulations with driver-license and rare SSN/TIN exposure
Technical writeup
Volkswagen Group of America, covering Volkswagen and Audi retail operations, told regulators that March 10, 2021 visibility into an unnamed vendor revealed marketing-and-sales datasets compiled 2014–2019 had been open to the internet during an August 2019–May 2021 window. SecurityWeek summarized Maine AG letters: >3.3 million North Americans—predominately basic contact and vehicle-interest metadata—while ~90,000 records carried financing-tier driver-license numbers and a thin tail with SSN/TIN class data. ZDNet echoed VW’s statement that >97% of rows were non-sensitive contact/vehicle-interest fields and credit-monitoring was offered to the high-risk subset.
Root cause
Third-party-managed datastore exposure / missing access controls on legacy sales-enablement exports