Breaches · 125 days ago
This was not just a customer-data leak. Exposed order details and password hashes turn a portal breach into a follow-on fraud problem, because attackers can use the records to impersonate Skoda and test reused credentials against other services.
Skoda says the online shop was taken offline after a portal software vulnerability was found and patched. The accessed data included names, addresses, email addresses, phone numbers, order details, and user account information, and no credit card data was stored on its systems.
The company has not said how many people were affected. Even without payment-card theft, the combination of account material and purchase history gives attackers enough context for convincing phishing and credential-stuffing against customers.
3 sources covering this story
Škoda warns of customer data breach after online shop hack
Škoda Auto, a wholly owned subsidiary of the Volkswagen Group, has disclosed a data breach after attackers hacked its online shop and stole the personal information of an undisclosed number of customers.
Škoda confirms unauthorized access to its online shop - Help Net Security
Customer account and contact information may have been exposed after unauthorized access to Škoda’s online shop system.
Skoda Data Breach Hits Online Shop Customers
Using a vulnerability in the portal, hackers accessed names, addresses, email addresses, and phone numbers.
Part of the PlainSec briefing for 2026-05-13