DisclosureLens
HackingRetail & ConsumerRetailData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDFinancial accountHighContained

VOLKSWAGEN GROUP OF AMERICA, INC.

bd_1ddbf202e4f260d8 · schema v1 · pii pii-v1

Severity

High

Discovered

Mar 10, 2021

Filed

Jun 10, 2021

To disclose

13 weeks

Affected

22,212state residents only

Linked

11 filings

Confidence

64%
Full breach record for VOLKSWAGEN GROUP OF AMERICA, INC.3 incidents on file

Volkswagen Group of America, Inc. notified customers that an unauthorized third party obtained limited personal information from a vendor used by Audi, Volkswagen, and authorized dealers. The data, gathered for sales and marketing from 2014-2019, included names, addresses, emails, phone numbers, VINs, and sensitive data like driver's license numbers. The incident was discovered in March 2021. Volkswagen engaged external experts and partnered with IDX to offer 24 months of credit monitoring and identity theft recovery services.

South Carolina clock SC CRA notice due13 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 587 days
discovery → filing · 13 weeks / 92 days

Aug 1, 2019

Begins

Mar 10, 2021

Discovered

Jun 10, 2021

Filed

vs. sector median

+6 wks slower

This filing is one of 11 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filingsup to 4d gap

Filing propagation · 11 filings · 11 states

View merged incident ↗
Maine State AGJun 10 · first
California State AGJun 10 · first
Massachusetts State AGJun 10 · first
Oregon State AGJun 10 · first
Hawaii State AGJun 10 · first
Idaho State AGJun 10 · first
South Carolina State AGJun 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.