AccidentalMisdeliveryData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
VOLKSWAGEN GROUP OF AMERICA, INC.
bd_0941ba49b48318db · schema v1 · pii pii-v1
Full breach record for VOLKSWAGEN GROUP OF AMERICA, INC. →Volkswagen Group of America, Inc. reported a data security incident involving a third-party vendor. Between August 2019 and May 2021, a vendor left electronic data unsecured, exposing customer contact information (names, addresses, emails, phone numbers) and vehicle details (VIN, make, model). Over 95% of sensitive data included driver's license numbers, with some SSNs and DOBs. Notification was sent in June 2021 offering 24 months of credit monitoring via IDX.
California clockDiscovered May 1, 2021 → Notified Jun 14, 202144d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_002ceb226a9ffd7eMaine State AGfiled 2021-06-10Candidate
- bd_1ddbf202e4f260d8South Carolina State AGfiled 2021-06-10Verified
- bd_a58d8faff4631ebaOregon State AGfiled 2021-06-10Verified
- bd_a70d19886d56a8b9Hawaii State AGfiled 2021-06-10Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_ace1b386f57a5432Delaware State AGfiled 2021-06-11(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-541768
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2021
- Raw hash
- 466cbde628a61212d7098e2a610bb459f46c984c366d47bb6e508184dfec17b2
Reporting entity
- Name
- VOLKSWAGEN GROUP OF AMERICA, INC.norm: volkswagen group of america
Victim entity
- Name
- VOLKSWAGEN GROUP OF AMERICA, INC.norm: volkswagen group of america
Incident
- Discovered
- May 1, 2021
- Materiality determined
- —
- Notification sent
- Jun 14, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- informed the appropriate authorities, including law enforcement and regulators
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 44d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 1, 2021→ Notified: Jun 14, 202144d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.