HackingData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
VOLKSWAGEN GROUP OF AMERICA, INC.
bd_ace1b386f57a5432 · schema v1 · pii pii-v1
Full breach record for VOLKSWAGEN GROUP OF AMERICA, INC. →Volkswagen Group of America, Inc. disclosed a data breach involving customer and buyer information obtained from a third-party vendor. The incident involved unsecured electronic data left by a vendor between August 2019 and May 2021. Affected data included names, addresses, emails, phone numbers, VINs, and sensitive identifiers like driver's license numbers, SSNs, and loan numbers. VW notified authorities, engaged cybersecurity experts, and partnered with IDX to offer 24 months of credit monitoring and identity theft recovery services to affected individuals.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_002ceb226a9ffd7eMaine State AGfiled 2021-06-10(1d gap)Candidate
- bd_0941ba49b48318dbCalifornia State AGfiled 2021-06-10(1d gap)Verified
- bd_1ddbf202e4f260d8South Carolina State AGfiled 2021-06-10(1d gap)Verified
- bd_a58d8faff4631ebaOregon State AGfiled 2021-06-10(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_a70d19886d56a8b9Hawaii State AGfiled 2021-06-10(1d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/06/Delaware-VWGoA-Notice-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 11, 2021
- Raw hash
- 769d634bfdf3154bbcc6cb88a616dc2db06b379496f457e9217f0d6f05d63b27
Reporting entity
- Name
- VOLKSWAGEN GROUP OF AMERICA, INC.norm: volkswagen group of america
Victim entity
- Name
- VOLKSWAGEN GROUP OF AMERICA, INC.norm: volkswagen group of america
Incident
- Discovered
- May 24, 2021
- Materiality determined
- —
- Notification sent
- Jun 11, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Informed appropriate authorities, including law enforcement and regulators
- Initial access
- supply_chain
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.