eAutoIndex: Vehicle Owner Data Accessed in Five Cantons
Security Flaw in Online Service – Five Cantons Investigate

In mid-August, large quantities of vehicle owner data from five cantons were automatically accessed via the "eAutoIndex" online portal. Aargau, Lucerne, Schaffhausen, Vaud, and Zug are affected. The cantons warn of potential fraud attempts and have filed charges or announced corresponding steps.
The accessed information consists of data that is generally publicly available: license plate number, along with the name and address of vehicle owners. Individuals who had blocked their data from public disclosure are, according to current findings, not affected.
Protection Mechanisms Were Circumvented
Particularly sensitive is not only the volume of data queried but also the nature of the access. Current findings indicate that the data was retrieved via a technical interface. This circumvented protection mechanisms that limit the number of queries via eAutoIndex.
The company responsible for operation has introduced additional technical access restrictions following the incident and is evaluating further measures. The identity of those behind the automated data retrieval and the purpose for which the data was collected are subjects of ongoing investigations.
The cantons have not yet publicly quantified the volume of data accessed. However, it is clear that this involved not individual queries but an automated compilation of owner data from five cantons.
Extortion Attempts Following Data Access
The incident has already escalated. Extortion attempts have been made against the operator of eAutoIndex and the Canton of Vaud. The five affected cantons have therefore already filed charges or intend to do so.
The cantons specifically warn that the collected information could be used for fraud attempts. Examples include deceptive payment requests for alleged fines, fees, vehicle inspections, or foreign road tolls.
Authorities therefore recommend scrutinizing unexpected letters, emails, or SMS messages. Caution is particularly advised when payment is demanded under time pressure or when prompted to enter personal or financial data via a link.
The Data Was Fundamentally Public
This case is also unique because no secret registry data was stolen. Under current law, the affected information is generally allowed to be publicly accessible. The Road Traffic Act permits cantons to disclose the name and address of vehicle owners, provided no disclosure block exists.
However, this does not mean that a massive automated collection of this information is unproblematic. A single owner inquiry and the systematic compilation of large data sets are different processes. The cantons see a potential risk of misuse precisely in this distinction.
Vehicle Registers Are Cantonally Organized
Responsibility for vehicle registers in Switzerland lies with the cantons. Online queries are made via different systems depending on the canton. The eAutoIndex serves as a platform for electronic owner information; for example, the Canton of Bern refers directly to eAutoIndex for its online queries.
The current incident thus also highlights a peculiarity of the Swiss system: data and the legal requirements for its publication are organized cantonally, while digital platforms can connect several cantons.
What Affected Individuals Can Do Now
Individuals who do not want their name and address to be publicly searchable via the Autoindex can generally have the disclosure of owner data blocked free of charge at the responsible Road Traffic Office. The five affected cantons explicitly highlight this option.
A previously implemented block protects data from public inquiry. According to the cantons, precisely those details that had already been blocked from public disclosure were not affected in the current incident.
For all others, heightened vigilance is currently key. Anyone receiving an unexpected invoice or payment request should not react via the link contained within it. It is safer to contact the relevant authority directly via its official website or telephone number.
Data Protection Authorities Monitor the Case
The incident also raises data protection questions. The Swiss Data Protection Act obliges responsible parties, under certain conditions, to report data security breaches to the Federal Data Protection and Information Commissioner (FDPIC). Such a report is particularly required if a breach is likely to result in a high risk to the personality or fundamental rights of the affected individuals.
It is not yet possible to definitively assess whether and to what extent such a report related to eAutoIndex has been made, based on the information published so far.
The Crucial Question Is Misuse
The current case illustrates a fundamental problem with digital registers: data can be legally publicly accessible yet still be collected on a large scale for a purpose that affected individuals hardly expect.
It is still unclear who is behind the automated retrievals and what has happened to the collected data. However, the extortion attempts already indicate a risk of misuse.
Therefore, for the cantons, the focus will not only be on who accessed the data. They must also clarify whether the technical protection mechanisms were sufficient and how comparable automated mass access can be prevented in the future.
The case is thus more than a technical glitch. It raises the question of how public data should truly remain public when modern systems enable the creation of extensive data collections from it in a short time.
Sources
- SRF: "eAutoIndex" – Data Access: Vehicle Owners Affected in Five Cantons, August 28, 2026
- Canton Zug / Joint statement by the five cantons: Vehicle Owner Data Leak, August 28, 2026
- FDPIC: Data Breach Guide
- FDPIC: Reporting Data Security Breaches
- Canton Bern: Information on Vehicle Owners
- Canton Aargau: Owner Data and Disclosure Block



