[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f22gysm0k4hg6o":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda488250f9","audi","Audi Data Breach","audiusa.com","2019-08-14T00:00:00.000Z","2021-07-23T06:31:33.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:42:27.959Z","Company disclosure and verified breach record","https:\u002F\u002Fwww.maine.gov\u002Fagviewer\u002Fcontent\u002Fag\u002F985235c7-cb95-4be2-8792-a1252b4f8318\u002F393b88dc-2f68-4aa7-8d97-f4b26ca58904.shtml",[15,17],"https:\u002F\u002Ftherecord.media\u002Fvolkswagen-discloses-data-breach-impacting-3-3-million-audi-drivers",2743539,"known",null,"unknown","Critical",[24,25,26,27,28,29,30,31],"Dates of birth","Driver's licenses","Email addresses","Names","Phone numbers","Physical addresses","Social security numbers","Vehicle details","\u003Cp>The Audi data breach is a significant automotive data leak that came to attention when automotive customer data held during sales, marketing, and lead processes by Audi of America and Volkswagen Group of America was accessible in an unsecured manner in a third-party service provider environment. The incident dates back to August 2019; company reporting indicates that the data was collected between 2014-2019 in customer, potential customer, and vehicle interest processes, and the unsecured environment was discovered and closed in 2021. In the LeakData record, this breach is tracked with 2,743,539 unique email addresses. Although broader company disclosures mention higher numbers of individuals, not all of these numbers correspond to unique email accounts; therefore, in this record, the scope of verified unique emails is taken as the basis for account control.\u003C\u002Fp>\u003Cp>The significance of this incident does not stem solely from the exposure of email addresses. The records contain data that can be directly linked to individuals in daily life, such as full names, phone numbers, physical addresses, and vehicle information. For some individuals, more sensitive information that can be used in identity verification processes, such as driver's license numbers, birth dates, and social security numbers, has also been affected. Since this distinction is critical, the breach should not be evaluated merely as a marketing list leak. The fact that vehicle ownership, address, and contact information are present in the same dataset should be handled with greater caution in terms of targeted fraud, fake dealership communications, phishing messages, and physical security risks.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data confirmed in the Audi breach include dates of birth, driver’s license information, email addresses, names, phone numbers, physical addresses, social security numbers, and vehicle details. Vehicle details may include identifiers such as the make, model, year, color, and equipment of the purchased, leased, or inquired-about vehicles. While this data alone can help identify a user, when used together it enables the creation of more realistic fraud scenarios. For example, an attacker could prepare messages that appear to be for a fake service appointment, warranty renewal, loan application, or dealer promotion using the vehicle make, contact information, and address of an individual.\u003C\u002Fp>\u003Cp>In this record, since the password, payment card, or active session key are not among the verified data types, the primary risk for users is more about authentication, social engineering, and physical address-based targeting rather than account takeover. Nevertheless, it is possible to match the email address with passwords from other leaks. Therefore, even if the Audi leakage is not a direct password leak, people using the same email address should use strong and unique passwords for their other accounts. The risk is higher for affected individuals if their social security number or driver's license information is involved; this information can be misused in opening new accounts, credit applications, or identity verification processes.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This data breach is associated with the Audi brand; however, its scope should not be interpreted as a general system breach affecting all global Audi users. The findings mainly point to customer, potential customer, sales, and marketing records based in the United States and Canada. While the majority of affected individuals have contact and vehicle interest information, a smaller group includes sensitive fields required during authentication and financial eligibility processes. Therefore, both the larger contact data set and the smaller sensitive data subgroup should be evaluated separately in the disclosure.\u003C\u002Fp>\u003Cp>The number 2,743,539 in the LeakData record represents the record tracked at the unique email address level. The larger number of individuals mentioned in company notifications may include records without an email address or different records belonging to the same person. Therefore, these numbers are not the same metric. The types of data included in the record are limited to verifiable fields; fields such as payment card, user password, bank account, health information, or full vehicle ownership history have not been added to this record. This approach is important to clearly convey the actual risk to the user without causing unnecessary panic.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>In the highest risk group are individuals who have shared their personal information in sales, leasing, financing, test drive, service, warranty, or dealer communication processes related to Audi or Volkswagen. It is not required for the person to be a vehicle owner; individuals who have been involved with the vehicle, received a quote, contacted a dealer, or filled out a marketing form may also fall within this scope. When email address, phone number, and physical address are included together, attackers can send more convincing messages. When vehicle information is also added, it becomes easier for the message to appear as if it is coming from a legitimate dealer, service, or financing representative.\u003C\u002Fp>\u003Cp>For affected users, the risk is more serious if their driver's license number, date of birth, or social security number is involved. These individuals should be more cautious about credit monitoring, identity verification alerts, and new account openings. The combination of a physical address with vehicle information can also increase targeted fraud or location-based risks for owners of high-value vehicles. For employees using a corporate email address, the threat can be carried into work emails through fake offers disguised as the company, fleet management, vehicle renewal, or financing messages.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users whose email addresses are included in this breach should first carefully examine unexpected messages regarding Audi, dealers, service, warranty, credit, insurance, or vehicle renewal. Instead of clicking on links in the message, operations should be carried out by directly typing the known official address of the relevant institution into the browser. The fact that a caller knows information such as name, vehicle model, address, or email alone is not proof of reliability; this information may have been obtained from leaked fields. No process that requires identity, driver's license, or social security number should be completed in a hurry.\u003C\u002Fp>\u003Cp>Users need to use a unique and strong password on their email account, enable two-factor authentication, and remove password reuse on other important accounts where the same email address is used. Although a password leak has not been confirmed in this incident, combining the email address with other data breaches is a common attack method. Users whose sensitive credentials may have been affected should periodically check their credit reports, new application notifications, and identity verification alerts. If a suspicious credit application, address change, vehicle financing request, or service transaction is detected, they should contact the relevant institution directly.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The Audi data breach demonstrates that prospective customer and marketing data in the automotive sector need to be protected as carefully as account information. The best long-term approach on the user side is to use separate passwords for each brand and service, make two-factor authentication standard for important accounts, and be cautious with messages related to high-value transactions such as vehicles, financing, and insurance. It should not be forgotten that old records can also pose a risk, as an email address may have been used over the years in many different applications, offers, and dealer forms.\u003C\u002Fp>\u003Cp>On the corporate side, dealer networks, marketing suppliers, customer relationship tools, and data sharing agreements should be subjected to regular security audits. Customer data held in third-party environments should not be retained longer than necessary, access should be restricted, and sensitive identity fields should be separated as much as possible. From the users' perspective, the practical lesson to be learned from this incident is to verify messages through an independent channel even if they contain personal details regarding a tool or financial matter. When communicating with a legitimate organization, the transaction number or request details should be confirmed through official customer service.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The purpose of querying the Audi data breach on LeakData is to show whether the email address is included in this verified automotive data leak. A match does not mean that all sensitive areas of the person are exposed; however, it indicates that the relevant email address is included in Audi-related customer or potential customer records. Therefore, the result should be considered as a warning, especially against frauds related to vehicle ownership, dealer communication, and financing processes.\u003C\u002Fp>\u003Cp>Users whose information has been matched should not postpone account security checks, should strengthen their email accounts, enable notifications on important financial accounts, and carefully verify communications requesting personal information. A lack of matching does not guarantee that the individual is not involved in other automotive, dealer, or marketing data breaches; it only means that there is no match in this Audi record. This record has been kept limited to verifiable data types to avoid adding incorrect fields, and the scope of the incident has been explained taking into account the difference between the number of unique emails and the broader company disclosure.\u003C\u002Fp>","","Audi Data Breach (2.7 Million Reported Records)","Audi Data Breach. 2.7 Million reported records were reported. Reported data: Dates of birth, Driver's licenses, Email addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Faudiusa_com.webp",false,{"name":39,"sector":40,"country":41,"website":9,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":20},"Audi of America \u002F Volkswagen Group of America","Automotive","United States"]