Clustered 6 filings across 6 jurisdictions · filing window Jun 10, 2021 → Jun 11, 2021. View entity profile → Other incidents for this victim →
incident inc_0aec7691a3424060 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA DE HI ME OR SC
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Aug 1, 2019 → May 24, 2021
When the intrusion reportedly occurred, per the linked filings
Mar 10, 2021
Reported by SOUTH CAROLINA AG filing
May 1, 2021
Reported by CALIFORNIA AG filing
May 24, 2021
Reported by MAINE AG, OREGON AG, DELAWARE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Volkswagen Group of America, Inc. reported a data breach caused by a third-party vendor that left electronic data unsecured. The breach occurred between August 2019 and May 2021 and was discovered on May 24, 2021. The incident affected 131 Maine residents, compromising their names and driver's license numbers. Affected individuals were notified on June 11, 2021, and offered twenty-four months of credit monitoring and identity theft protection services.
Affected (this filing): 131
Volkswagen Group of America, Inc. reported a data security incident involving a third-party vendor. Between August 2019 and May 2021, a vendor left electronic data unsecured, exposing customer contact information (names, addresses, emails, phone numbers) and vehicle details (VIN, make, model). Over 95% of sensitive data included driver's license numbers, with some SSNs and DOBs. Notification was sent in June 2021 offering 24 months of credit monitoring via IDX.
Volkswagen Group of America, Inc. notified customers that an unauthorized third party obtained limited personal information from a vendor used by Audi, Volkswagen, and authorized dealers. The data, gathered for sales and marketing from 2014-2019, included names, addresses, emails, phone numbers, VINs, and sensitive data like driver's license numbers. The incident was discovered in March 2021. Volkswagen engaged external experts and partnered with IDX to offer 24 months of credit monitoring and identity theft recovery services.
Volkswagen Group of America, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-06-10. The breach was discovered on 5/24/2021. 90,184 individuals were affected. Notice was sent on 6/11/2021.
Affected (this filing): 90,184
Volkswagen Group of America reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2021/06.10. Breach type: Hackers/Unauthorized Access. 6,261 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
Volkswagen Group of America, Inc. disclosed a data breach involving customer and buyer information obtained from a third-party vendor. The incident involved unsecured electronic data left by a vendor between August 2019 and May 2021. Affected data included names, addresses, emails, phone numbers, VINs, and sensitive identifiers like driver's license numbers, SSNs, and loan numbers. VW notified authorities, engaged cybersecurity experts, and partnered with IDX to offer 24 months of credit monitoring and identity theft recovery services to affected individuals.