A new report from Quebec's commission on ethics in science and technology has put connected cars back in the headlines, describing the modern vehicle as a "computer on wheels" and identifying 12 major privacy risks in how these cars collect and share data (Source: The Canadian Press, 2026). The coverage has focused on the consumer angle, which is the right conversation for drivers. For the people who run security and IT, the more useful detail sits in one incident the report cites, because it is not really a story about cars at all.
The report points to a 2024 failure in which a misconfigured cloud database left the GPS history and personal data of roughly 800,000 Volkswagen electric vehicles openly accessible on the internet for months (Source: The Canadian Press, 2026). No attacker broke in. Nothing was exploited. The data was simply left exposed. That is the enterprise attack-surface problem in miniature, told through a car.
The breach was not sophisticated, and that is the point
The Volkswagen exposure was not an isolated event. In 2025, grow-light and IoT manufacturer Mars Hydro left a database of 2.7 billion records open on the internet without any authentication, including device identifiers and the Wi-Fi network names and passwords of the devices connected to it (Source: Asimily, 2026). Like the Volkswagen case, this was not a break-in. The data was publicly readable because no one secured the place it was stored.
These are the failures that define modern exposure, and they are almost entirely preventable. Misconfiguration accounts for roughly 23% of all cloud security incidents, 70% of cloud environments contain at least one publicly exposed resource, and 40% of organizations admit they have poor visibility into how their own cloud is configured (Source: 2026 cloud security analyses; Fortinet 2026). Gartner has long held that nearly all cloud security failures trace back to the customer rather than the provider. The technology is rarely the weak point. How it is configured, stored, and watched is.
Every connected device is now part of your attack surface
The reason this matters far beyond the automotive industry is scale. There were 21.1 billion active connected devices worldwide in 2025, a figure heading toward 30 billion by 2027 (Source: IoT Analytics). Vehicles are one category. So are the cameras, sensors, building-management systems, printers, and fleet trackers that quietly attach to enterprise networks and ship their data to third-party clouds no one on the security team configured.
Attackers have noticed. Connected devices rose to 19% of all observed exploit activity in 2025, up from 16% the year before, and threat actors now launch an average of 820,000 attempts against these devices every day, a 46% increase year over year (Source: Forescout, 2026; threat telemetry 2026). Ransomware groups increasingly use a compromised device as their way in, with attacks against operational technology up 46% in 2025 (Source: Nozomi Networks, 2026). The devices are rarely the target. They are the entrance.
The data problem behind the device problem
There is a second lesson in the connected-car story that maps directly onto the enterprise. A vehicle collects data, sends it to an external cloud, and hands it to a third-party provider the owner never evaluated. The Quebec report concludes that the traditional model of individual consent no longer holds up in that ecosystem, because no one can reasonably track where their data goes (Source: The Canadian Press, 2026).
Enterprises face the same loss of control under a different name: data sprawl. Sensitive information ends up in cloud services, connected tools, and vendor platforms that were never inventoried, and the organization inherits the exposure without the visibility. You cannot protect data when you do not know it exists or where it lives, and that gap is exactly what a misconfigured store turns into a headline.
What this means for security leaders
The connected car is a preview of a shift that has already reached every organization. Three changes in how you think about your environment follow from it.
Treat every connected device as an endpoint. If it collects or transmits data, it belongs in your asset inventory and your monitoring, even when it looks nothing like a laptop.
Monitor your external attack surface continuously. The exposures that cause damage now are misconfigured cloud stores and internet-facing devices you did not know were reachable. These change constantly, so a point-in-time audit does not catch them.
Know where your sensitive data lives. Discovery is the prerequisite for protection, because data you cannot locate is data you cannot secure.
Where Quick Intelligence fits
This is the work we do for our clients. Quick Intelligence provides External Risk Monitoring that continuously maps your external attack surface across cloud, applications, and connected tools using agentless, API-based discovery, surfacing exposed assets and misconfigurations in real time. Our Sensitive Data Discovery identifies where sensitive information lives across your files, endpoints, and cloud systems, so the data that would become a headline is found and secured before anyone else finds it. Both run under the watch of our 24/7 Canadian-based security operations centre, with one team that owns the outcome. That is what we mean when we say we take your success personally.
See where your organization stands with our complimentary Security Infrastructure Resilience Assessment at quickintel.com/assessment, or book a consultation at quickintel.com/contact.
Frequently asked questions
Was the Volkswagen connected-car data exposure a hack? No. The data of roughly 800,000 vehicles was exposed because a cloud database was misconfigured and left publicly accessible, not because an attacker exploited a vulnerability. Misconfiguration of this kind is the single largest preventable cause of cloud data exposure.
Why do connected devices expand an organization's attack surface? Every connected device collects and transmits data, usually to an external cloud, and most are not covered by the tools a security team runs. Each device and each place its data is stored becomes a potential point of exposure, which is why connected devices now account for a growing share of exploit activity.
What is external attack surface management? It is the continuous discovery and monitoring of everything your organization exposes to the internet, including cloud services, applications, and connected devices. Because these exposures change constantly, continuous monitoring catches misconfigurations and unknown assets that a periodic audit would miss.
How do enterprises secure IoT and connected devices? Start by inventorying every connected device as an endpoint, monitor your external attack surface continuously for misconfigurations and exposed assets, and locate where sensitive data is stored so it can be protected. Managed detection then watches for the activity that signals a device has been compromised.