Site navigation

Toyota Notifies Customers of Exposed Information

Michael Edgar

,

Toyota attack
Toyota Financial Services (TFS) issued a warning following a data breach which may have exposed sensitive personal and financial information. 

TFS, which is a subsidiary of the global automotive giant Toyota Motor Corporation, issued a warning to its customers about a significant data breach following an unauthorised access detected last month in some of its European and African systems. 

“Toyota Financial Services Europe & Africa recently identified unauthorised activity on systems in a limited number of its locations. We took certain systems offline to investigate this activity and to reduce risk, and have also begun working with law enforcement,” said the company in a statement at the time of the attack. 

Insofar, the exact number of victims has not been released, and the company says it is working diligently on an internal investigation into the incident. 

The original breach was carried out by the Medusa ransomware group, a ransomware-as-a-service (RaaS)  which first appeared on the scene in 2021. The threat actors asked for $8 million (£6.3m) to delete data allegedly stolen from TFS.

The company now has a 10-day window to respond to their extortion, with the option to extend the deadline for an additional $10K (£7.9K) per day

In a letter sent to impacted German users, obtained by Heise, the breach could have exposed information such as full names, postal code and address, contract details and International Bank Account Numbers (IBANs).


Recommended reading


Upon detection of the unauthorised access, Toyota shut down certain systems, which resulted in an impact on customer services. Since it likely did not engage in negotiations with the cybercriminals, the leaked data has since been made accessible on Medusa’s dark web extortion portal. 

Compromised data could lead to phishing attacks, social engineering, scams, financial fraud, and identity theft for victims. Toyota has assured customers that it will update them if the investigation reveals any further data exposure. 

This announcement comes on the tail end of a year which saw a record high in ransomware attacks. According to the latest NCC Group Threat Pulse report, ransomware attacks rose 81% year-on-year, and claimed over 50% more victims than last year. 

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data