HackingData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
VOLKSWAGEN GROUP OF AMERICA, INC.
bd_1ddbf202e4f260d8 · schema v1 · pii pii-v1
Full breach record for VOLKSWAGEN GROUP OF AMERICA, INC. →Volkswagen Group of America, Inc. notified customers that an unauthorized third party obtained limited personal information from a vendor used by Audi, Volkswagen, and authorized dealers. The data, gathered for sales and marketing from 2014-2019, included names, addresses, emails, phone numbers, VINs, and sensitive data like driver's license numbers. The incident was discovered in March 2021. Volkswagen engaged external experts and partnered with IDX to offer 24 months of credit monitoring and identity theft recovery services.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_002ceb226a9ffd7eMaine State AGfiled 2021-06-10Candidate
- bd_0941ba49b48318dbCalifornia State AGfiled 2021-06-10Verified
- bd_a58d8faff4631ebaOregon State AGfiled 2021-06-10Verified
- bd_a70d19886d56a8b9Hawaii State AGfiled 2021-06-10Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_ace1b386f57a5432Delaware State AGfiled 2021-06-11(1d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/Volkswagen.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2021
- Raw hash
- 54ea059a745bd3a2f41eab5809e664bb74aad2680dca44545d080de1c74b929d
Reporting entity
- Name
- VOLKSWAGEN GROUP OF AMERICA, INC.norm: volkswagen group of america
Victim entity
- Name
- VOLKSWAGEN GROUP OF AMERICA, INC.norm: volkswagen group of america
Incident
- Discovered
- Mar 10, 2021
- Materiality determined
- —
- Notification sent
- Jun 11, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Informed appropriate authorities, including law enforcement and regulators
- Initial access
- supply_chain
Compliance
- Time to disclose
- 13 weeks(92 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.