Volkswagen App Vulnerabilities Expose Global User Data in Latest Cybersecurity Scare
A newly uncovered set of weaknesses in Volkswagen’s connected vehicle app has exposed personal customer data and detailed maintenance logs across its global user base—raising renewed concerns over the automaker’s digital security posture.
These critical flaws, identified in 2025, allowed unauthorized parties to access sensitive information with minimal effort—requiring nothing more than the car’s VIN, a number typically visible through the windshield of most vehicles.
This revelation marks the second data security lapse for Volkswagen within half a year, following a massive cloud storage leak in December 2024 that exposed data from more than 800,000 electric vehicles.
Discovery Rooted in Real-World Use
The breach was brought to light not through abstract research, but through a practical experience. Ethical hacker Vishal Bhaskar stumbled upon the issue after buying a used Volkswagen last year. Upon trying to connect his new vehicle to the “My Volkswagen” app, Bhaskar noticed that verification codes (OTPs) were still being sent to the previous owner’s phone—revealing a glaring oversight in account reassignment protocols.
Instead of walking away, Bhaskar decided to investigate further. He discovered that the app lacked basic protections against repeated OTP attempts—no rate-limiting, no account lockouts. Using Burp Suite to monitor app traffic, he crafted a Python script capable of brute-forcing the 4-digit code in a matter of minutes.

The breakthrough wasn’t the end — it marked the first step into uncharted territory.

Severe API Flaws Uncovered in Volkswagen Infrastructure
In an in-depth security analysis, Bhaskar revealed three major weaknesses lurking within Volkswagen’s digital framework:
Plaintext Access to Sensitive Credentials: One misconfigured API endpoint was found leaking internal access keys — including usernames, passwords, session tokens, and integration credentials for critical third-party platforms like Salesforce and payment gateways. This oversight offered attackers a direct line into core systems.

VIN Used to Uncover Sensitive Customer Info:
A separate system flaw made it possible to retrieve detailed personal information—such as full names, contact numbers, email addresses, home addresses, and vehicle registration history—simply by entering a car’s Vehicle Identification Number (VIN). This vulnerability effectively turned a basic identifier into a gateway to customer service records and private data.

Service Records Laid Bare Through VIN Lookup:
An additional flaw allowed unrestricted access to a vehicle’s entire service timeline—everything from maintenance visits and customer-reported issues to satisfaction survey responses. No authentication was needed; a valid VIN was all it took to view these records, effectively leaving private aftersales data unprotected.

Modern Cars, Exposed: Critical Flaws Left Drivers and Data at Risk
A series of overlooked security gaps created a high-stakes scenario where anyone with technical know-how could tap into a vehicle’s inner workings and its owner’s private life. These vulnerabilities enabled unauthorized access to:
- Real-time vehicle tracking, engine diagnostics, fuel levels, and tire pressure.
- Personally identifiable information such as home addresses and driver’s license data.
- Full service histories, including past complaints and satisfaction surveys.
- Remote vehicle control capabilities—without the owner’s consent.
“This wasn’t just about cars—it was about people,” said Denis Laskov, Chief Hacker at EY IL, who helped bring the issue to light. “With this kind of access, a bad actor could trace your movements, know where you sleep, where you work, and how to reach you—online or offline.”
The vulnerabilities were responsibly disclosed to Volkswagen by researcher Bhaskar on November 23, 2024. After months of coordinated dialogue, the automaker confirmed all issues had been resolved by May 6, 2025.
As cars evolve into always-connected devices, cybersecurity is no longer optional—it’s foundational. Experts caution that without robust digital defenses, the conveniences of smart vehicles could come at the cost of driver safety and privacy.




