News: 1759481721

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Criminals take Renault UK customer data for a joyride

(2025/10/03)


Renault UK customers are being warned their personal data may be in criminal hands after one of its supplier was hacked.

In an email sent to affected individuals this week, seen by The Register , the French carmaker said attackers accessed the supplier's systems and made off with customer details including names, gender, phone numbers, email and postal addresses, and vehicle registration and identification numbers.

"Your data was included, which means the attackers have access to some or all of the following information," states the letter. Renault stressed that no bank details were involved, since the supplier in question did not hold financial records.

[1]

Renault UK boss Adam Wood tried to calm nerves, stressing that the crooks hadn't touched the company's own kit. The stolen data, he said, came from a third-party supplier, not Renault's systems. "None of our own systems have been compromised," Wood insisted.

[2]Jaguar Land Rover gets £1.5B government jump-start after cyber breakdown

[3]Car giant Stellantis says customer data nicked after partner vendor pwned

[4]So you CAN turn an entire car into a video game controller

[5]Nissan to let 100,000 Aussies and Kiwis know their data was stolen in cyberattack

[6]California cops confused after trying to give ticket to self-driving car

According to posts on [7]online forums , customers of Renault's sister brand Dacia have also received similar warnings.

Renault did not confirm how many customers are affected and has not answered questions from The Register about the scale of the digital break-in or the identity of the breached supplier. The company's message states the incident has been "contained and removed" and the vendor is taking "all appropriate actions."

[8]

[9]

The breach has been reported to regulators, according to Renault.

An ICO spokesperson told us: "Renault UK has reported an incident and we are making enquiries."

[10]

Naturally, customers are being advised to watch out for unsolicited messages requesting personal information. "You should never share your passwords online or on the phone – Renault UK will never ask you for this information," the letter warns.

The breach comes against a backdrop of mounting attacks on the automotive sector, with carmakers proving a rich target thanks to the mountains of personal data gathered during sales, servicing and financing.

JLR stuck in neutral as losses skyrocket amid cyberattack cleanup [11]READ MORE

Jaguar Land Rover learned that lesson the hard way last month, when attackers breached its systems to [12]pilfer troves of data . The fallout was severe enough that the company has been forced to halt production lines at multiple sites as it scrambles to contain the incident. The disruption this week prompted [13]the UK government to step in with a loan package , underlining just how critical the manufacturer is to the wider economy.

Stellantis, meanwhile, admitted weeks ago that one of its suppliers had suffered a cyber intrusion, [14]exposing the details of its North American customers .

Renault's letter to customers wraps up with the usual apology.

[15]

"Data privacy is of the utmost importance to us. We deeply regret that this has occurred and wish to apologise again," it states, pointing customers with questions to Renault's privacy policy page or its Data Protection Officer.

For now, Renault drivers can only hope the stolen files don't end up in the usual dark web dumps or phishing campaigns. Without clarity on how many customers are affected or who was breached, the incident adds another reminder that even if your bank details are safe, the rest of your personal data is often just one supplier compromise away from exposure. ®

Get our [16]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aN-etKRtkfzOahuML6uFWgAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2025/09/29/jlr_government_loan/

[3] https://www.theregister.com/2025/09/22/stellantis_breach/

[4] https://www.theregister.com/2025/06/27/renault_clio_racing_controller/

[5] https://www.theregister.com/2024/03/14/nissan_oceania_100k_affected/

[6] https://www.theregister.com/2025/09/29/california_cops_self_driving/

[7] https://www.reddit.com/r/CyberCrime/comments/1nwcidr/renault_uk_customers_have_data_stolen_in_cyber/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aN-etKRtkfzOahuML6uFWgAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aN-etKRtkfzOahuML6uFWgAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aN-etKRtkfzOahuML6uFWgAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2025/09/16/jlr_global_shutdown/

[12] https://www.theregister.com/2025/09/10/jaguar_land_rover_breach/

[13] https://www.theregister.com/2025/09/29/jlr_government_loan/

[14] https://www.theregister.com/2025/09/22/stellantis_breach/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aN-etKRtkfzOahuML6uFWgAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://whitepapers.theregister.com/



Anothger 3rd party hack

ComicalEngineer

You gave your details to Renault, they entrusted them to a 3rd party which you probably didn't realise, then the 3rd party got hacked and your personal details are out in the wild. Who is actually responsible for this Renault or the anonymous 3rd party, and who will protect the individuals concerned and cover their losses from the data breach?

Too many companies trusting *our* data to 3rd parties.

Re: Anothger 3rd party hack

Test Man

Renault.

We gave our details to Renault. It doesn't matter if they entrusted said data to someone else, we gave our data to Renault.

So it's Renault who will cover any losses and protect the individual.

Re: Anothger 3rd party hack

hoola

It is a convenient way to shift responsibility.

Renault are the data owner and is they contract a third party it should make no difference. Renault must still be responsible however the third party is also culpable. Just like any big business hiding behind contracts, outsourcing and third parties is standard practice so that those who ultimately should be responsible are not.

Just like all the double glazing companies with a 10 year guarantee but the business is wound up every other year.

Three Midwesterners, a Kansan, a Missourian and an Iowan,
all appearing on a quiz program, were asked to complete this sentence:
"Old MacDonald had a . . ."

"Old MacDonald had a carburetor," answered the Kansan.
"Sorry, that's wrong," the game show host said.
"Old MacDonald had a free brake alignment down at the
service station," said the Missourian.
"Wrong."
"Old MacDonald had a farm," said the Iowan.
"CORRECT!" shouts the quizmaster. "Now for $100,000, spell 'farm.'"
"Easy," said the Iowan. "E-I-E-I-O."