One misconfigured cloud folder exposed exactly where 800,000 cars had been parked
In late 2024, a whistleblower alerted German publication Der Spiegel and the ethical hacking group Chaos Computer Club to a data exposure at CARIAD SE, Volkswagen Group's automotive software subsidiary. What they found: a misconfigured Amazon Web Services storage system that had, for months, left vehicle telemetry and precise geolocation data openly accessible online - no sophisticated hacking required.
What was actually exposed
The exposed dataset included precise GPS coordinates showing exactly where and when vehicles were parked - accurate to within 10 centimeters for Volkswagen and Seat models, and within roughly 10 kilometers for Audi and Skoda vehicles. For approximately 460,000 of the affected vehicles, researchers could combine that location data with owner names, email addresses and phone numbers, making it possible to identify specific individuals and track their movement patterns over time. Germany accounted for the largest share of affected vehicles, roughly 300,000, with meaningful numbers also affecting Norway, Sweden, the United Kingdom, the Netherlands and several other European countries.

This wasn't a sophisticated hack. It was an unlocked door that had been left open for months.
— Marqstats Analyst Team
How something this basic happened at this scale
CARIAD characterized the root cause as a misconfiguration rather than a deliberate security flaw, affecting two IT applications. The underlying technical failure, per independent security researchers who examined the incident, involved a Java Virtual Machine monitoring and reporting tool with an improperly secured cloud storage configuration, discoverable through standard security reconnaissance tools. Once located, the exposed data required no advanced exploitation technique to access - it was, in effect, sitting in a publicly reachable location without the access controls that should have been in place from the start.
Cariad maintained that the exposed data was pseudonymized rather than directly containing information like passwords or payment details, and that combining the datasets to identify specific individuals would have required meaningful technical effort. Independent researchers who actually performed that combination work demonstrated it was achievable without extraordinary sophistication, particularly for the roughly 460,000 vehicles where location data could be cross-referenced with contact information.
Why this matters beyond one company's mistake
This incident lands squarely within a broader industry pattern this market's own analysis has already identified: automotive data management has consolidated almost entirely around first-party OEM cloud platforms following the collapse of third-party data brokers. That consolidation was framed, reasonably, as a way for automakers to regain direct control over sensitive vehicle data rather than routing it through external intermediaries. The Cariad incident is a useful corrective to reading that shift as a straightforward privacy improvement: centralizing enormous volumes of precise location data within a single organization's cloud infrastructure doesn't eliminate privacy risk, it concentrates it. A single misconfiguration at one company can now expose data that, under the older, more fragmented broker model, would have been spread across multiple separate systems.
The counter-argument: doesn't every data platform face this same risk, regardless of who operates it?
A fair objection is that misconfiguration risk isn't unique to first-party OEM cloud platforms specifically - any organization storing large volumes of sensitive data in cloud infrastructure, broker or automaker, faces comparable exposure to human configuration error, and singling out the first-party model for this risk may be somewhat unfair given that third-party brokers were never large enough to demonstrate whether they'd have handled equivalent data volumes any more securely. This is a reasonable point, and it's true that misconfiguration risk is a general cloud security challenge rather than one specific to automaker-operated infrastructure. What the Cariad incident does add to the conversation, though, is a concrete illustration that the scale of first-party OEM platforms, now managing tens of millions of vehicles each, means any single configuration failure has correspondingly larger blast radius than a smaller, more fragmented data ecosystem would have produced.
What this means for automakers and data governance teams
- Automakers operating large-scale connected vehicle cloud platforms should treat configuration audit frequency and fine-grained access governance, such as Databricks Unity Catalog or AWS IAM session controls, as a core operational requirement, not an optional enhancement.
- Regulators and consumer advocates evaluating the shift toward first-party OEM data platforms should weigh this concentration risk explicitly, not just the privacy benefits of eliminating third-party broker intermediaries.
- Consumers and fleet operators should ask automakers directly about data retention periods and access-control auditing practices, given that pseudonymization alone did not prevent individual vehicle owners from being identifiable in this incident.
Why the disclosure process itself matters
The way this incident came to light is worth examining separately from the technical failure itself. A whistleblower first alerted both Der Spiegel and the Chaos Computer Club, rather than the exposure being discovered through Cariad's own internal security monitoring. The Chaos Computer Club then gave the company a 30-day window to fix the vulnerability before making the issue public, a responsible disclosure practice common in the security research community. Cariad has stated it closed the specific vulnerability the same day it was formally notified by the CCC. But the gap between when the misconfiguration first occurred and when it was ultimately discovered spans months, according to reporting - meaning the exposure existed and was potentially accessible for a meaningful period before anyone outside the company identified it.

This sequencing detail matters for evaluating automaker data governance practices generally: the incident wasn't caught by Cariad's own internal auditing processes, it was caught by an external security researcher acting on a whistleblower tip. That distinction, internal detection versus external discovery, is a genuinely meaningful signal about the maturity of an organization's own security monitoring infrastructure.
What this incident does and doesn't tell us about EV-specific risk
It's worth being precise that this incident isn't evidence that electric vehicles specifically carry more inherent privacy risk than internal combustion vehicles - the exposure occurred because of how Cariad's cloud infrastructure was configured, not because of anything unique to EV powertrains or battery systems. The affected vehicles happened to be electric because Cariad manages connected services predominantly for Volkswagen Group's EV lineup during this period, but the underlying lesson, that centralized cloud data platforms require rigorous, continuously audited access controls, applies equally to any automaker's connected vehicle fleet, regardless of propulsion type.
The full market picture
Marqstats' complete global automotive data management market analysis, including the full data governance and security landscape, is available in the linked report below.
Related reportGlobal Automotive Data Management Market Size, Share & Forecast 2025 – 2030