Renault UK has notified customers that their personal information may have been compromised following a cyberattack on one of its third-party suppliers. The breach did not affect Renault’s own internal systems, as confirmed by company officials, but rather originated from an external service provider that held customer data. The compromised information includes names, gender, phone numbers, email addresses, postal addresses, vehicle registration numbers, and vehicle identification numbers (VINs). Renault has emphasized that no bank or financial account details were involved in the breach, as the supplier did not store such information. Customers of Renault’s sister brand Dacia have also reportedly received similar notifications, suggesting the breach may have impacted multiple brands under the Renault Group. The company has not disclosed the total number of affected customers or the identity of the breached supplier. Renault has stated that the incident has been contained and that the supplier is taking all appropriate actions to address the breach. The company has reported the incident to relevant regulatory authorities, including the UK Information Commissioner’s Office (ICO), which has confirmed it is making enquiries. Customers have been advised to remain vigilant for unsolicited communications that may attempt to exploit the stolen data for phishing or other malicious purposes. Renault has reassured customers that it will never request passwords or sensitive information via email or phone. The breach highlights the growing risk of supply-chain and third-party attacks in the automotive sector, where attackers increasingly target external vendors to access sensitive data. The incident follows a series of similar breaches affecting other automakers and their suppliers, underscoring the need for robust third-party risk management. Renault’s response has included direct communication with affected individuals, cooperation with the compromised supplier, and engagement with authorities to ensure compliance and transparency. The company has not answered media questions regarding the scale of the breach or the specific nature of the attack. This event serves as a reminder for organizations to assess the security posture of their partners and suppliers, as vulnerabilities in the supply chain can have significant repercussions for customer privacy and brand reputation. The breach has prompted discussions about the adequacy of current security measures in the automotive industry and the importance of timely notification and remediation. Customers are urged to monitor their accounts and communications for signs of identity theft or fraud in the aftermath of the breach.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting indicated the third-party data breach warning extended to customers of both Renault and Dacia in the UK, broadening the known scope of the incident beyond Renault UK alone.
Renault UK said the incident had been isolated and contained, remediation work was underway, and relevant authorities had been notified in coordination with the affected external provider. The company also warned customers to be alert to phishing or other unsolicited requests for personal information.
Renault UK disclosed that a cyberattack on one of its third-party service providers, not Renault’s internal systems, may have compromised customer personal and vehicle-related data including names, contact details, registration numbers, and VINs. The company said bank and financial account details were not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.