Škoda Auto , a member of the Volkswagen Group and one of Europe's largest automakers, has confirmed that it has suffered a serious data breach after a cyberattack targeted its online store . According to the company, unknown attackers exploited a security flaw in its e-commerce platform , gaining temporary unauthorized access to systems containing personal customer data.
The case is particularly worrying, as Škoda is one of the main pillars of the Volkswagen group, with a presence in dozens of markets worldwide. The Czech automaker, with a history of 130 years, employs more than 34,000 people and in 2025 recorded sales of more than 27 billion euros, delivering more than one million vehicles.
How the attack took place
As the company itself revealed , the perpetrators exploited a vulnerability in the software of its online sales platform. After detecting the breach, Škoda immediately proceeded to correct the security gap and informed the relevant data protection authorities .
See also: Foxconn confirms ransomware attack on factories

At the same time, a special IT forensics team to investigate the incident and analyze the attackers' modus operandi. The company said that the problem was detected through internal security monitoring, which likely limited the scope of the breach.
Škoda did not disclose how long the attackers remained in the systems or the total number of customers affected. It remains unknown at this time whether there was any contact with the perpetrators or a possible ransom demand.
Škoda: What data was exposed?
According to the official update, cybercriminals gained access to personal customer information, including:
- Names and addresses
- Email addresses
- Phone numbers
- Order details
- Login credentials
- Password hashes
Although passwords were not stored in plain text, access to hashed credentials is still considered a serious risk, especially if users reuse the same passwords across different services.
The company stressed that full credit card details were not stored in the affected systems, as payment processing is carried out exclusively by external providers. However, Škoda urged customers to closely monitor their banking transactions and account movements.
See also: Canvas hack: Instructure paid ransom to ShinyHunters

Concern about phishing and credential attacks
One of the biggest problems after such attacks is not only the leakage of data, but also its potential exploitation in secondary phishing and credential stuffing attacks.
Škoda warned that attackers could use the stolen credentials to send fraudulent emails, SMS or phone calls that appear to be from the company. Cybersecurity experts point out that such attacks often exploit users' trust in well-known brands, leading victims to fake login pages or malicious links.
At the same time, the possibility of reusing the same passwords across multiple services increases the risk of other online accounts being compromised.
The automotive industry is the target of cyberattacks
The Škoda incident is not an isolated case. In recent years, car manufacturers have increasingly been at the center of cyberattacks, as they manage huge amounts of personal data, vehicle information, and connected services.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Just a few months ago, Renault and Dacia revealed a data breach that affected customers in the UK, exposing vehicle information, license plates and personal customer details.
See also: Hugging Face: Fake OpenAI Privacy Filter Repo with 244K downloads
Even more serious was the incident that hit Jaguar Land Rover, where a cyberattack caused massive operational disruption. The attack affected the company's manufacturing and retail operations, leading to a 43% drop in wholesale sales and financial losses exceeding $220 million.

Cybersecurity is becoming a critical factor for automotive companies
The Škoda case demonstrates that automakers are no longer just facing production and supply chain challenges, but also growing cyber threats. As vehicles, after-sales services and online ecosystems become increasingly connected, companies are being called upon to invest significantly more resources in data protection and the resilience of digital infrastructure .
For consumers, this particular breach serves as yet another reminder that the security of personal data now depends not only on them, but also on the level of protection implemented by the large multinational companies with which they interact daily.
Source: www.bleepingcomputer.com
