Toyota confirms third-party data breach impacting customers

Teilen:

Toyota confirmed that customer data was exposed in a third-party data breach after a threat actor leaked an archive of 240GB of stolen data on a hacking forum.

“We are aware of the situation. The issue is limited in scope and is not a system wide issue,” Toyota told BleepingComputer when asked to validate the threat actor’s claims.

The company added that it’s “engaged with those who are impacted and will provide assistance if needed,” but has yet to provide information on when it discovered the breach, how the attacker gained access, and how many people had their data exposed in the incident.

One day later, a spokesperson clarified in a new statement shared with BleepingComputer that Toyota Motor North America’s systems were “not breached or compromised,” and the data was stolen from what appears to be “a third-party entity that is misrepresented as Toyota.”

When asked to share the name of the breached third-party entity, the spokesperson said that Toyota Motor North America was “not at liberty to disclose” that information.

Employee and customer data exposed

ZeroSevenGroup (the threat actor who leaked the stolen data) says they breached a U.S. branch and were able to steal 240GB of files with information on Toyota employees and customers, as well as contracts and financial information,

They also claim to have collected network infrastructure information, including credentials, using the open-source ADRecon tool that helps extract vast amounts of information from Active Directory environments.

“We have hacked a branch in United States to one of the biggest automotive manufacturer in the world (TOYOTA). We are really glad to share the files with you here for free. The data size: 240 GB,” the threat actor claims.

“Contents: Everything like Contacts, Finance, Customers, Schemes, Employees, Photos, DBs, Network infrastructure, Emails, and a lot of perfect data. We also offer you AD-Recon for all the target network with passwords.”

While Toyota hasn’t shared the date of the breach, BleepingComputer found that the files had been stolen or at least created on December 25, 2022. This date could indicate that the threat actor gained access to a backup server where the data was stored.

​Last year, Toyota subsidiary Toyota Financial Services (TFS) warned customers in December that their sensitive personal and financial data was exposed in a data breach resulting from a Medusa ransomware attack that impacted the Japanese automaker’s European and African divisions in November.

Months earlier, in May, Toyota disclosed another data breach and revealed that the car-location information of 2,150,000 customers was exposed for ten years, between November 6, 2013, and April 17, 2023, because of a database misconfiguration in the company’s cloud environment.

Weeks later, it found two additional misconfigured cloud services leaking Toyota customers’ personal information for over seven years.

Following these two incidents, Toyota said it implemented an automated system to monitor cloud configurations and database settings in all its environments to prevent such leaks in the future.

Multiple Toyota and Lexus sales subsidiaries were also breached in 2019 when attackers stole and leaked what the company described at the time as “up to 3.1 million items of customer information.”

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:18 pm, Jan. 22, 2025
Wetter-Symbol 4°C
L: 2° | H: 5°
broken clouds
Luftfeuchtigkeit: 87 %
Druck: 1003 mb
Wind: 7 mph W
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:52 am
Sonnenuntergang: 4:31 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
2° | 5°°C 1 mm 100% 18 mph 89 % 1005 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
5° | 11°°C 1 mm 100% 25 mph 89 % 1004 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
2° | 5°°C 1 mm 100% 6 mph 96 % 1013 mb 0 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
1° | 7°°C 0 mm 0% 16 mph 95 % 1013 mb 0 mm/h
Mo. Jan. 27 9:00 pm
Wetter-Symbol
4° | 9°°C 1 mm 100% 26 mph 92 % 996 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 4 mph 84 % 1003 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 5 mph 89 % 1004 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 7 mph 87 % 1005 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 9 mph 83 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 16 mph 76 % 1000 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
8° | 8°°C 1 mm 100% 18 mph 71 % 999 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
6° | 6°°C 0.8 mm 80% 16 mph 72 % 1002 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 11 mph 75 % 1004 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€99,969.99
-2.28%
Ethereum(ETH)
€3,132.50
-2.03%
XRP(XRP)
€3.05
-0.16%
Fesseln(USDT)
€0.96
-0.05%
Solana(SOL)
€252.98
4.07%
Dogecoin(DOGE)
€0.345479
-4.05%
USDC(USDC)
€0.96
0.01%
Shiba Inu(SHIB)
€0.000019
-2.75%
Pepe(PEPE)
€0.000014
-3.41%
Peanut das Eichhörnchen(PNUT)
€0.348999
-2.58%
Nach oben scrollen