2026-08-29 · view entry permalink →
Six Swiss cantons disclose bulk-harvesting of vehicle-owner data after an unknown actor bypassed per-person rate limits on public lookup portals, with extortion attempts against the platform operator and canton Vaud
On 2026-08-28, five Swiss cantons — Vaud, Aargau, Lucerne, Schaffhausen and Zug — issued a joint statement, and canton Valais a separate one, disclosing that an unknown party had automatically harvested vehicle-owner data at scale from their public online lookup services in mid-August (cash.ch, 2026-08-28). For the five-canton group the vector was eAutoIndex, a shared lookup platform operated by Viacar AG (Aarau) for multiple cantonal road-traffic offices; the platform normally receives more than 10,000 legitimate owner queries a day across the five cantons (cash.ch, 2026-08-28). The joint statement records that the actor circumvented eAutoIndex's own anti-abuse control — ordinarily capped at five queries per person per day — to compile registration-plate numbers together with the associated owner's name and address at volume (cash.ch, 2026-08-28). Cantonal officials characterise this as abuse of a legitimate public-disclosure mechanism rather than a conventional data breach: no authentication was bypassed, the retrieval interface exposed only data already publicly disclosable under Swiss federal road-traffic law, and no data that owners had opted to block from public disclosure was exposed (cash.ch, 2026-08-28).
Canton Valais reported a separate incident the same day affecting "ecari", a different vehicle-lookup module supplied by an external partner to its own cantonal road-traffic and navigation service. There, the actor went beyond the intended query logic of the lookup interface through additional extractions to also obtain approximate owner birthdates — a materially more sensitive field than the plate/name/address set exposed via eAutoIndex, and one not normally reachable through an ordinary query (Blick, 2026-08-28). Both the eAutoIndex operator (Viacar AG) and the canton of Vaud state they were subject to extortion attempts following the harvesting, which they did not act on (Blick, 2026-08-28). The five eAutoIndex cantons have filed or plan to file criminal complaints, and Viacar AG has introduced additional technical access restrictions on eAutoIndex and is evaluating further controls (cash.ch, 2026-08-28). Valais separately states it has filed its own criminal complaint and has hardened access security on the affected "ecari" system (Blick, 2026-08-28). Neither the identity nor the number of actors involved is known, and no exploitation of the underlying road-traffic office IT systems — as opposed to the public lookup interfaces — is reported by any cantonal authority (cash.ch, 2026-08-28; Blick, 2026-08-28).
No source names the specific bypass technique (IP rotation, missing server-side session or device fingerprinting, distributed request sourcing, or another anti-abuse gap) — an open question worth flagging for any defender who operates a similar public per-identity rate-limited lookup service. Cantonal officials warn of a plausible follow-on fraud vector: attackers or downstream buyers of the harvested plate/name/address/approximate-birthdate combination could send deceptively authentic-looking demands for fake fines, vehicle-inspection fees, or foreign toll charges (cash.ch, 2026-08-28).
Ordinarily, the number of queries on 'eAutoIndex' per person and per day is limited to five.
According to current findings, the retrieval of the data occurred via a technical interface that exclusively permitted access to publicly viewable data. It can be ruled out that blocked data was exposed, according to Probst. It is not an actual data leak but rather the abusive use of a public information-lookup facility.
The public-data leak also affected Valais: the 'ecari' search module, supplied by a partner external to the road-traffic and navigation service, was likewise targeted. Through additional extractions, the hacker was also able to access approximate date-of-birth data that is not normally accessible via an ordinary query.