Volkswagen's Data Breach: CCC Exposes Millions of Vehicle Location Data Stored Unencrypted

2025-01-02

The Chaos Computer Club (CCC) revealed that the Volkswagen Group systematically collected and stored movement data from hundreds of thousands of VW, Audi, Skoda, and Seat vehicles for extended periods. This data, including driver information, was left unprotected and accessible on the internet. The breach affected private vehicles, corporate fleets, and even government agencies, including sensitive data from the German Federal Intelligence Service and a US Air Force base. The CCC highlighted that the data collection and long-term storage were problematic, exacerbated by poor security. The findings were published in Der Spiegel and will be detailed at the 38th Chaos Communication Congress (38C3) in Hamburg.

Read more

Hackers Face Lawsuit After Exposing Polish Train Manufacturer's Manipulation

2024-12-27

The Chaos Computer Club (CCC) is raising funds for three hackers who revealed at the 37C3 conference how Polish rail vehicle manufacturer Newag manipulated its trains to be repairable only in its own workshops. Newag reacted with a 90s-style aggressive lawsuit, pursuing both criminal and civil charges. The legal costs have already reached €30,000. The CCC is calling for donations to cover legal and other expenses. The hackers' research did not involve any illegal replacement of train components. The CCC believes Newag's lawsuit aims to prevent future publications about these 'illegal instructions,' emphasizing that only the content teams decide who speaks at the congress. The 38C3 congress will continue reporting on this case.

Read more