Volkswagen Allegedly Hit by Ransomware Attack as 8Base Claims Sensitive Data Theft
Volkswagen Group recently issued a statement regarding claims by the ransomware group 8Base, which alleges the theft and leakage of sensitive data from the automaker. The company confirmed that its core IT infrastructure remains secure but did not…
Volkswagen Group recently issued a statement regarding claims by the ransomware group 8Base, which alleges the theft and leakage of sensitive data from the automaker. The company confirmed that its core IT infrastructure remains secure but did not provide detailed information about the incident, which has raised concerns of a potential third-party compromise.
The ransomware group 8Base, active since early 2023, reported a major breach of Volkswagen, claiming to have exfiltrated confidential files on September 23, 2024. They threatened to release the data by September 26, although no samples have been leaked yet. The group listed the data on its dark web site, which allegedly includes financial records, personal employee files, employment contracts, and confidentiality agreements. This could potentially affect Volkswagen's global operations, including brands such as Audi, Porsche, Bentley, Lamborghini, Skoda, SEAT, and Cupra.
8Base is known for using Phobos ransomware and double-extortion tactics, focusing on data theft and coercion to pressure victims into payment. The group has reportedly targeted over 400 organizations, often gaining access through phishing or purchasing credentials from initial access brokers.
They threatened to release the data by September 26, although no samples have been leaked yet.
A Volkswagen spokesperson acknowledged the incident but assured that the company’s primary IT systems remain unaffected. The response suggests a possible compromise through a supplier, partner, or subsidiary. Volkswagen, headquartered in Wolfsburg, Germany, operates 153 production plants worldwide and employs hundreds of thousands, making any data exposure a significant concern.
No customer data breach has been reported; however, the potential inclusion of personal and financial details raises compliance issues under the EU's General Data Protection Regulation (GDPR), which could lead to fines of up to 4% of global revenue if confirmed. Cybersecurity experts emphasize the importance of enhanced third-party risk management and monitoring, as such attacks often exploit vulnerabilities in supply chains.
The ongoing investigation highlights the increasing threats facing critical industries, such as automotive manufacturing.
Based on reporting by Cyber Security News.
