VOLKSWAGEN GROUP OF AMERICA, INC.
ent_019e242591f3b9e681c10bcedca1203c
Disclosures
13
State AG · 12 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,300,000
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- VOLKSWAGEN GROUP OF AMERICA, INC.
- Normalized
- volkswagen group of america— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493004OKBY1W66Q5Y80
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- VOLKSWAGEN AKTIENGESELLSCHAFT— per GLEIF relationship records
Disclosure history (13)newest first
- Massachusetts State AGas victim2025-05-16
Volkswagen Group of America, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-05-16. 1 Massachusetts residents were affected.
- New Hampshire State AGas victim2021-06-14
Volkswagen Group of America (VWGoA) notified New Hampshire AG of a breach affecting 3.3 million US/Canadian customers. A vendor left data unsecured between Aug 2019 and May 2021. Data included contact info, VINs, and for ~90k individuals, driver's licenses, SSNs, and loan numbers. VWGoA engaged law enforcement and forensic consultants, offering 24 months of credit monitoring via IDX. Notification began June 11, 2021.
- Indiana State AGas victim2021-06-11
Volkswagen Group of America, Inc reported a data breach to the Indiana Attorney General. 875 Indiana residents were affected. 90,184 individuals affected in total.
- Delaware State AGas victim2021-06-11
Volkswagen Group of America, Inc. disclosed a data breach involving customer and buyer information obtained from a third-party vendor. The incident involved unsecured electronic data left by a vendor between August 2019 and May 2021. Affected data included names, addresses, emails, phone numbers, VINs, and sensitive identifiers like driver's license numbers, SSNs, and loan numbers. VW notified authorities, engaged cybersecurity experts, and partnered with IDX to offer 24 months of credit monitoring and identity theft recovery services to affected individuals.
- Montana State AGas victim2021-06-11
Volkswagen Group of America, Inc. notified Montana of a data security incident involving customer information obtained from a vendor. The vendor left electronic data unsecured between August 2019 and May 2021. Data included names, addresses, emails, phone numbers, and vehicle details. Notification sent June 14, 2021.
- Maine State AGas victim2021-06-10
Volkswagen Group of America, Inc. reported a data breach caused by a third-party vendor that left electronic data unsecured. The breach occurred between August 2019 and May 2021 and was discovered on May 24, 2021. The incident affected 131 Maine residents, compromising their names and driver's license numbers. Affected individuals were notified on June 11, 2021, and offered twenty-four months of credit monitoring and identity theft protection services.
- California State AGas victim2021-06-10
Volkswagen Group of America, Inc. notified California residents that a third-party vendor left electronic data unsecured between August 2019 and May 2021. The incident exposed contact information (name, address, email, phone) and vehicle details for customers and interested buyers. Sensitive data including driver's license numbers, and in rare cases SSNs and dates of birth, was also compromised. The company engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring.
- South Carolina State AGas victim2021-06-10
Volkswagen Group of America, Inc. notified customers that an unauthorized third party obtained limited personal information from a vendor used by Audi, Volkswagen, and authorized dealers. The data, gathered for sales and marketing from 2014-2019, included names, addresses, emails, phone numbers, VINs, and sensitive data like driver's license numbers. The incident was discovered in March 2021. Volkswagen engaged external experts and partnered with IDX to offer 24 months of credit monitoring and identity theft recovery services.
- Massachusetts State AGas victim2021-06-10
Volkswagen Group of America, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-06-10. 958 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2021-06-10
Volkswagen Group of America, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-06-10. The breach was discovered on 5/24/2021. 90,184 individuals were affected. Notice was sent on 6/11/2021.
- Hawaii State AGas victim2021-06-10
Volkswagen Group of America reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2021/06.10. Breach type: Hackers/Unauthorized Access. 6,261 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
- Idaho State AGas victim2021-06-10
Volkswagen Group of America (VWGoA) disclosed a breach affecting over 3.3 million US and Canadian customers. An unauthorized third party obtained customer data from a vendor used by Audi and VW dealers between Aug 2019 and May 2021. Data included contact info, VINs, and for ~90k individuals, driver's licenses, SSNs, and financial account numbers. VWGoA notified law enforcement, engaged forensic consultants, and offered 24 months of credit monitoring via IDX. Idaho had 4,825 affected residents.
- Illinois State AGas victim2021-01-01
VOLKSWAGEN GROUP OF AMERICA, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-216). The register records the breach as discovered on March 10, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.