Stolen From Audi and Volkswagen Available To Be Purchased

Opt-in to Cyber Safety. Multiple layers of protection for your devices, online privacy and more.

Last week, Volkswagen Group of America, Inc. (VWGoA) declared that more than 3.3 million customers and interested buyers had their information exposed in a tremendous data breach, that occurred after a vendor exposed unsecured data on the Internet.

The vendor is a company that provides services to Audi, Volkswagen, and some authorized dealers related to digital sales and marketing activities.

This Monday, cybercriminals put the data stolen from the German motor vehicle manufacturer on sale on an infamous hacking forum.

In a data breach notification, the organization declared:

The data included some or all of the following contact information about you: first and last name, personal or business mailing address, email address, or phone number.

In some instances, the data also included information about a vehicle purchased, leased, or inquired about, such as the Vehicle Identification Number (VIN), make, model, year, color, and trim packages.


While this incident is still under investigation, Audi and Volkswagen think approximately 3.3 million individual customers and interested buyers were impacted, with more or less 163,000 individuals living in Canada.

The Audi and Volkswagen Stolen Data on Sale on a Notorious Hacking Forum

On Monday, a known seller of data stolen during data breaches made the Audi and Volkswagen data available to be purchased on a popular hacking forum.

According to a post on the forum, the sold data consists of over 5 million records, with 3,862,231 records being leads and 1,792,278 records in the sales database.

Audi and Volksvagen forum post


According to Motherboard, a hacker that goes by 000 declared that the information included email addresses and Vehicle Identification Numbers (VIN). The attacker also published two samples of the data, which contained full names, email addresses, mailing addresses, and phone numbers.

When contacted, seven of the people included in the samples confirmed that at least one piece of their information published by the cybercriminals was authentic.

The seller, who obtained the data in March 2021 after finding it in an unsecured Azure Blob container, stated it didn’t include any Social Security Numbers nor drivers’ license details…