Volkswagen Group—Cariad software flaw exposed precise location and personal data of 800,000 VW, Audi, Seat and Skoda EV owners for months
A misconfigured AWS cloud storage system operated by Cariad, Volkswagen's software subsidiary, left terabytes of vehicle telemetry from roughly 800,000 electric vehicles publicly accessible for months. Data included battery levels, ignition status and, for about 460,000 vehicles, GPS location accurate to within 10cm (VW/Seat) or 10km (Audi/Skoda), which could be cross-referenced with linked customer accounts to reveal names, addresses, phone numbers and detailed movement profiles. Germany's Chaos Computer Club discovered and reported the exposure; Cariad closed access the same day, in late December 2024.
Scoring Impact
| Topic | Direction | Relevance | Contribution |
|---|---|---|---|
| Data Security | -against | primary | -1.00 |
| User Privacy | -against | secondary | -0.50 |
| Overall incident score = | -0.362 | ||
Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.64)× agency (negligent ×0.5)
Evidence (2 signals)
TechCrunch: Volkswagen leak exposed precise location data on hundreds of thousands of vehicles across Europe for months
TechCrunch confirmed the Cariad exposure lasted months before discovery, corroborating the scale and technical details of the AWS misconfiguration.
Der Spiegel investigation: VW/Cariad left location data on 800,000 EVs exposed on unprotected cloud storage
Der Spiegel's original investigation, based on a tip from the Chaos Computer Club, found terabytes of Cariad telemetry data - including GPS coordinates accurate to 10cm for VW/Seat and 10km for Audi/Skoda - stored on misconfigured AWS infrastructure and linkable to owners' personal data.