Škoda disclosed that attackers exploited a vulnerability in its online shop software, gaining temporary unauthorized access to the e-commerce environment and prompting the company to take the shop offline. The automaker said the affected system processes customer names, addresses, contact details, order information, and login credentials, and that passwords were stored as cryptographic hashes. Škoda notified the relevant data protection authority, remediated the flaw, and brought in a specialized IT forensics team to investigate the incident.
The company said technical analysis indicates access to data stored in the shop was theoretically possible, but logging and protocol limitations mean it cannot determine whether information was actually viewed or copied, or to what extent. Škoda added that full payment card data was not directly accessible because transactions are handled by third-party payment providers, while urging customers to change reused passwords, remain alert for phishing messages, avoid suspicious links and attachments, and monitor bank and credit card statements for unusual activity.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Škoda notified the relevant data protection supervisory authority and publicly disclosed the security incident affecting its online shop. The company said payment card details were not directly accessible because payment processing is handled by third-party providers.
In response to the intrusion, Škoda took its online shop offline and fixed the exploited vulnerability. It also engaged a specialized IT forensics team to investigate the incident.
Škoda said attackers exploited a vulnerability in its online shop software and gained temporary unauthorized access to the system. The company stated that customer data stored in the shop could theoretically have been accessed, but logging limitations prevent determining whether data was actually viewed or copied.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourceskoda-auto.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.