9 ms·
VW says data breach at vendor impacted 3.3M people in North America
- azinman2 5y ago> The sensitive data was comprised of driver license numbers in more than 95% of cases. A small number of records included additional data like dates of birth, Social Security numbers and account numbers. Wow so only that. My gosh, why is that information in a 3rd party vendor's db at all?!
- vmception 5y agoNew Fullz (real people's IDs) for sale. Finally a way to cash out your illicitly earned crypto. Make a new Coinbase account in someone else's name, and a new brokerage account in their name too. They'll never know! Access via remote desktop from a compromised computer near their zip code, check the markets those are everywhere too! That person will never know either! You can buy your favorite penny stock with the funds in their name and be seen as a having a good trading year in your own real identity and clean funds. Not advocating anything, this is what happens all day every day.
- garyfirestorm 5y agoFor you to cash out your crypto wouldn’t you need to transfer it to your account? Isn’t that enough for IRS to knock on your door?
- vmception 5y agoyou missed the part where you make another account in someone else's name because you had bought their ID the IRS and DOJ will go knocking on their door and parade them around, writing "no matter what assets you trade, you can't hide and our financial system is immune from illicit funds"
- jacquesm 5y agoexactly.
- jacquesm 5y agoWith a paper trail a mile wide leading to the wrong door: sure. 'Your account' is their account. By the time the money hits a real account in control of the perp it will be offshore for sure.
- tempodox 5y agoIn the US, the DMVs of many (all?) states sell the data they have on you to 3rd parties without you having a say in it. So there's no telling how many DBs have copies of your data stored. https://www.caranddriver.com/features/a32035408/dmv-selling-driver-data/ https://www.caranddriver.com/features/a32035408/dmv-selling-...
- hn_throwaway_99 5y agoI've said this before, but at this point I think the better solution is to just assume name, phone, email, address, DoB, social security number and drivers license number are fully public, because they pretty much already are. Then, from, that perspective, companies shouldn't treat that information as individually identifiable because it's likely already public.
- deleted 5y ago[deleted]
- neolog 5y agoThe problem is that I don't want that information to be public.
- hn_throwaway_99 5y agoI mean, I want a pony, too. I'm not disagreeing with you that I wish this information weren't public, but the fact of the matter is that it is public, and breaches are possible even if you have no relationship with company that was breached (see Equifax). So all I'm advocating is that we accept the reality of the situation and start requiring more stringent forms of identification.
- swiley 5y agoIt's fine for it to identify you but does not in any way authenticate you. People who cared understood that in the 50s.
- raverbashing 5y ago> companies shouldn't treat that information as individually identifiable because it's likely already public. But that would require someone to think for 2 seconds instead of following procedures that are probably literally 50 years old so we can't have that And it seems this is even worse in Canada for some reason, where they're over reliant on US procedures and "ways of thinking" (in some aspects).
- paco3346 5y agoI work for an automotive vendor and this kind of thing keeps me up at night. The automotive vendor space is... lacking in technology. It's amazing what little thing we can do from a technological standpoint that impresses the OEMs. Also, the way most of these vendor relationships work is that the provider collects data, passes it on to the dealership and program management company (third party that OEMs hire to handle the vendor relationships) who then passes it to the OEM itself. Often there are 3-4 copies of your data. SSNs _are_ a surprise though. That's usually exclusively for credit approvals and every vendor I've ever worked with takes stuff seriously.
- rkagerer 5y agoThe automaker does not believe sensitive information is involved in Canada. I guess it's just coincidence within an hour of reading about this I got a phone call claiming to be from my Canadian VW dealer looking to refund an amount they overcharged on labor the last time I had my car in. It was the most convincing scam attempt I've ever encountered. Caller ID matched the correct, local number for the dealer. The guy sounded enough like the service rep I dealt with the last few times to fool me, and knew to go by his nickname instead of the full name found on the invoice and email signatures. He sounded authentically embarrassed, and spoke with the right amount of "um's" and "ah's" you'd expect from a service guy. They knew exactly when I had my car in. The work had been complex and there were a number of billing adjustments made at the time, so I wasn't too surprised. I even thanked him for his honesty for correcting it. Saying they didn't have my credit card on file, he offered to either leave the amount on file as a credit or take my card number to refund it immediately. He wasn't very pushy about which to choose, and to be honest it wasn't until he asked for my expiry date that I got more suspicious. Funny part is at one point I asked if he'd heard about the hack. It clearly caught him off guard, and after a long pause he was like "No... there's been no official word on that yet". I called the dealership right afterward, and the receptionist said she hadn't heard about it either and acted as if it would be totally normal for him to collect my credit card information (oops). Still wary, I reached out to him by email - and got confirmation it wasn't him, and that they're working with law enforcement. Obviously I canceled my card. I can't help but wonder if the hackers might have gotten away with it had they gained control of their email as well. I can't imagine how many people are falling victim to this scam as you read this, and wonder if other dealerships are being similarly targeted. VW really has to step up their messaging.
- axiosgunnar 5y agoSpooky story! One thing I cant stop thinking about is... aren‘t credit cards incredibly insecure? I assume we are currently stuck with them for legacy reasons, right? Aren't things like authentication tokens or whatever „solved“ issues? Like, I have never heard of similar attack vectors for PayPal or Stripe? Or do I have a logic error in my thinking and all payment systems will always have attack vectors similar to stealing a number?
- Lio 5y agoA couple of years ago my local VW dealer we’re giving out free OBD Bluetooth adapters to Golf owners. All you had to do was install VW’s app and let them have all the real time data from your car. I said, no thanks. VW don’t strike me as a company committed to either security or privacy (and neither do any other car manufacturers I can think of). This was exactly the kind of breach I had in mind back then.