ctipilot.ch

Swiss cantons eAutoIndex/ecari vehicle-registry data-harvesting incident

incident · incident:swiss-cantons-eautoindex-databulk-harvest-2026-08

An unknown actor bypassed the per-person daily query limit on the eAutoIndex public vehicle-owner lookup platform (Viacar AG), shared by cantons Vaud, Aargau, Lucerne, Schaffhausen and Zug, to harvest plate/name/address data at scale in mid-August 2026; canton Valais separately reported additional extractions on its own 'ecari' platform exposing approximate owner birthdates. Both Viacar AG and canton Vaud report subsequent extortion attempts (cash.ch/AWP, Der Bund, Blick, watson.ch, 2026-08-28).

Coverage timeline
1
first 2026-08-29 → last 2026-08-29
Peak priority
high
1 high
Sources cited
4
4 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
eAutoIndex (Viacar AG)ecari

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Collection TA0009

T1119Automated Collection×1

Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.

Evidence: 2026-08-29/swiss-cantons-eautoindex-vehicle-registry-data-harvesting · ATT&CK page ↗

Story timeline

  1. 2026-08-29Six Swiss cantons disclose bulk-harvesting of vehicle-owner data after an unknown actor bypassed per-person rate limits on public lookup portals, with extortion attempts against the platform operator and canton Vaud
    active-threatsAn attacker defeated Switzerland's cantonal vehicle-registry rate limits at scale, and two operators were then extorted

Where this entity is cited

  • active-threats1

Source distribution

  • blick.ch1 (25%)
  • cash.ch1 (25%)
  • derbund.ch1 (25%)
  • watson.ch1 (25%)

explore in graph

Entries about Swiss cantons eAutoIndex/ecari vehicle-registry data-harvesting incident (1)

2026-08-29 · view entry permalink →

HIGHNATOB2

Six Swiss cantons disclose bulk-harvesting of vehicle-owner data after an unknown actor bypassed per-person rate limits on public lookup portals, with extortion attempts against the platform operator and canton Vaud

On 2026-08-28, five Swiss cantons — Vaud, Aargau, Lucerne, Schaffhausen and Zug — issued a joint statement, and canton Valais a separate one, disclosing that an unknown party had automatically harvested vehicle-owner data at scale from their public online lookup services in mid-August (cash.ch, 2026-08-28). For the five-canton group the vector was eAutoIndex, a shared lookup platform operated by Viacar AG (Aarau) for multiple cantonal road-traffic offices; the platform normally receives more than 10,000 legitimate owner queries a day across the five cantons (cash.ch, 2026-08-28). The joint statement records that the actor circumvented eAutoIndex's own anti-abuse control — ordinarily capped at five queries per person per day — to compile registration-plate numbers together with the associated owner's name and address at volume (cash.ch, 2026-08-28). Cantonal officials characterise this as abuse of a legitimate public-disclosure mechanism rather than a conventional data breach: no authentication was bypassed, the retrieval interface exposed only data already publicly disclosable under Swiss federal road-traffic law, and no data that owners had opted to block from public disclosure was exposed (cash.ch, 2026-08-28).

Canton Valais reported a separate incident the same day affecting "ecari", a different vehicle-lookup module supplied by an external partner to its own cantonal road-traffic and navigation service. There, the actor went beyond the intended query logic of the lookup interface through additional extractions to also obtain approximate owner birthdates — a materially more sensitive field than the plate/name/address set exposed via eAutoIndex, and one not normally reachable through an ordinary query (Blick, 2026-08-28). Both the eAutoIndex operator (Viacar AG) and the canton of Vaud state they were subject to extortion attempts following the harvesting, which they did not act on (Blick, 2026-08-28). The five eAutoIndex cantons have filed or plan to file criminal complaints, and Viacar AG has introduced additional technical access restrictions on eAutoIndex and is evaluating further controls (cash.ch, 2026-08-28). Valais separately states it has filed its own criminal complaint and has hardened access security on the affected "ecari" system (Blick, 2026-08-28). Neither the identity nor the number of actors involved is known, and no exploitation of the underlying road-traffic office IT systems — as opposed to the public lookup interfaces — is reported by any cantonal authority (cash.ch, 2026-08-28; Blick, 2026-08-28).

No source names the specific bypass technique (IP rotation, missing server-side session or device fingerprinting, distributed request sourcing, or another anti-abuse gap) — an open question worth flagging for any defender who operates a similar public per-identity rate-limited lookup service. Cantonal officials warn of a plausible follow-on fraud vector: attackers or downstream buyers of the harvested plate/name/address/approximate-birthdate combination could send deceptively authentic-looking demands for fake fines, vehicle-inspection fees, or foreign toll charges (cash.ch, 2026-08-28).

Ordinarily, the number of queries on 'eAutoIndex' per person and per day is limited to five.

According to current findings, the retrieval of the data occurred via a technical interface that exclusively permitted access to publicly viewable data. It can be ruled out that blocked data was exposed, according to Probst. It is not an actual data leak but rather the abusive use of a public information-lookup facility.

cash.ch (AWP/Keystone-SDA wire, relaying the joint cantonal statement) 2026-08-28

The public-data leak also affected Valais: the 'ecari' search module, supplied by a partner external to the road-traffic and navigation service, was likewise targeted. Through additional extractions, the hacker was also able to access approximate date-of-birth data that is not normally accessible via an ordinary query.

Blick (Romandie), relaying the État de Vaud / canton Valais statements 2026-08-28
incident29 Aug 04:09Zmulti-sourceOpen finding ↗