Volkswagen Allegedly Hacked in Ransomware Attack as 8Base Claims Data Leak
Volkswagen Group is currently investigating claims from the 8Base ransomware group, which alleges the theft of sensitive company data.
Volkswagen Group is currently investigating claims from the 8Base ransomware group, which alleges the theft of sensitive company data.
The German automaker has confirmed the security of its core IT systems but acknowledges the potential for a breach through third-party suppliers, raising concerns about the full extent of the incident.
The 8Base ransomware group, known for its activities since early 2023, announced on Sat, Sep 23, 2024, that it had targeted one of the largest automotive manufacturers globally. The group has connections to the Phobos ransomware family and primarily targets small to mid-sized businesses worldwide. Although Europol-led operations disrupted their infrastructure in February 2025, concerns remain about potential future activities by affiliates.
8Base employs double-extortion tactics and claims to have exfiltrated significant confidential information, threatening to leak it by Thu, Sep 26. While no public data dump has occurred, the group has listed allegedly stolen file types on its dark web portal.
Invoices and receipts. Accounting documents and financial records. Personal employee files and employment contracts. Personnel records and certificates. Confidentiality agreements and non-disclosure documents.
Volkswagen Group is currently investigating claims from the 8Base ransomware group, which alleges the theft of sensitive company data.
Security experts identify 8Base primarily as a data extortion operation aiming to pressure victims into paying a ransom.
A Volkswagen spokesperson has confirmed awareness of the incident but emphasized no impact on the company's primary IT infrastructure. This suggests the breach may have originated from a connected entity, such as a supplier or partner.
Volkswagen, with 153 production plants globally and renowned brands like Audi, Porsche, and Lamborghini, faces significant risks from any data exposure. The company has not confirmed whether customer data was compromised.
This alleged breach underscores the increasing trend of cyberattacks targeting large corporations via their supply chains. Verification of 8Base's claims could result in scrutiny from regulatory bodies if personal employee data and financial records are exposed.
Under the EU's General Data Protection Regulation (GDPR), a substantiated breach could lead to substantial fines. As investigations continue, this incident highlights the importance of robust third-party risk management and continuous security monitoring in the automotive industry.
Based on reporting by GBHackers.
