ctipilot.ch
← Back to the live brief
HIGHNATOB2incident

Six Swiss cantons disclose bulk-harvesting of vehicle-owner data after an unknown actor bypassed per-person rate limits on public lookup portals, with extortion attempts against the platform operator and canton Vaud

first published 2026-08-29 04:09 UTCrun 2026-08-29T0409Z-intel4 sourcesmulti-source

On 2026-08-28, five Swiss cantons — Vaud, Aargau, Lucerne, Schaffhausen and Zug — issued a joint statement, and canton Valais a separate one, disclosing that an unknown party had automatically harvested vehicle-owner data at scale from their public online lookup services in mid-August (cash.ch, 2026-08-28). For the five-canton group the vector was eAutoIndex, a shared lookup platform operated by Viacar AG (Aarau) for multiple cantonal road-traffic offices; the platform normally receives more than 10,000 legitimate owner queries a day across the five cantons (cash.ch, 2026-08-28). The joint statement records that the actor circumvented eAutoIndex's own anti-abuse control — ordinarily capped at five queries per person per day — to compile registration-plate numbers together with the associated owner's name and address at volume (cash.ch, 2026-08-28). Cantonal officials characterise this as abuse of a legitimate public-disclosure mechanism rather than a conventional data breach: no authentication was bypassed, the retrieval interface exposed only data already publicly disclosable under Swiss federal road-traffic law, and no data that owners had opted to block from public disclosure was exposed (cash.ch, 2026-08-28).

Canton Valais reported a separate incident the same day affecting "ecari", a different vehicle-lookup module supplied by an external partner to its own cantonal road-traffic and navigation service. There, the actor went beyond the intended query logic of the lookup interface through additional extractions to also obtain approximate owner birthdates — a materially more sensitive field than the plate/name/address set exposed via eAutoIndex, and one not normally reachable through an ordinary query (Blick, 2026-08-28). Both the eAutoIndex operator (Viacar AG) and the canton of Vaud state they were subject to extortion attempts following the harvesting, which they did not act on (Blick, 2026-08-28). The five eAutoIndex cantons have filed or plan to file criminal complaints, and Viacar AG has introduced additional technical access restrictions on eAutoIndex and is evaluating further controls (cash.ch, 2026-08-28). Valais separately states it has filed its own criminal complaint and has hardened access security on the affected "ecari" system (Blick, 2026-08-28). Neither the identity nor the number of actors involved is known, and no exploitation of the underlying road-traffic office IT systems — as opposed to the public lookup interfaces — is reported by any cantonal authority (cash.ch, 2026-08-28; Blick, 2026-08-28).

No source names the specific bypass technique (IP rotation, missing server-side session or device fingerprinting, distributed request sourcing, or another anti-abuse gap) — an open question worth flagging for any defender who operates a similar public per-identity rate-limited lookup service. Cantonal officials warn of a plausible follow-on fraud vector: attackers or downstream buyers of the harvested plate/name/address/approximate-birthdate combination could send deceptively authentic-looking demands for fake fines, vehicle-inspection fees, or foreign toll charges (cash.ch, 2026-08-28).

Ordinarily, the number of queries on 'eAutoIndex' per person and per day is limited to five.

According to current findings, the retrieval of the data occurred via a technical interface that exclusively permitted access to publicly viewable data. It can be ruled out that blocked data was exposed, according to Probst. It is not an actual data leak but rather the abusive use of a public information-lookup facility.

cash.ch (AWP/Keystone-SDA wire, relaying the joint cantonal statement) 2026-08-28

The public-data leak also affected Valais: the 'ecari' search module, supplied by a partner external to the road-traffic and navigation service, was likewise targeted. Through additional extractions, the hacker was also able to access approximate date-of-birth data that is not normally accessible via an ordinary query.

Blick (Romandie), relaying the État de Vaud / canton Valais statements 2026-08-28

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Collection TA0009
T1119Automated Collection

Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.