INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Škoda's Online Shop Compromised by Hackers Exposing Customer Data

| 2026-05-12 17:07 HIGH LOW DATA BREACH
Executive Summary
AI-generated
Škoda Auto, a wholly owned subsidiary of the Volkswagen Group, disclosed a data breach after attackers hacked its online shop and stole the personal information of an undisclosed number of customers. The attack occurred on 2026-05-12 when threat actors exploited an unspecified vulnerability in the software of Škoda's e-commerce portal to gain temporary unauthorized access to the store system. The customer information accessed by the threat actors includes names, addresses, contact information, order information, and login credentials, but not financial information as it was processed exclusively by payment service providers. Following the breach, Škoda reported the incident to relevant authorities and fixed the security flaw exploited in the attack, while also warning affected individuals of potential phishing attacks targeting them due to reused credentials.
Technical Mitigations AI-generated
• Patch the vulnerability in Škoda's e-commerce portal software to prevent similar attacks. • Monitor for phishing attempts targeting affected customers and advise them to be extra vigilant regarding suspicious emails, text messages, or phone calls. • Use a unique password for each online account and avoid reusing login credentials across multiple platforms.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
RoverRover
Target & Sectors
FIVE_EYES FIVE_EYES automotiveautomotive retailretail
Incident Timeline
‎2026/05/12
Škoda Auto, a wholly owned subsidiary of the Volkswagen Group, disclosed a data breach after attackers hacked its online shop and stole the personal information of an undisclosed number of customers.
victims 34,000 employees
financial $220 company
Tactical Metrics
Metrics
victims
34,000
Employees
Metrics
financial
220,000,000
Company
Intelligence Sources
BleepingComputer 2026-05-12