TFS, which is a subsidiary of the global automotive giant Toyota Motor Corporation, issued a warning to its customers about a significant data breach following an unauthorised access detected last month in some of its European and African systems.
“Toyota Financial Services Europe & Africa recently identified unauthorised activity on systems in a limited number of its locations. We took certain systems offline to investigate this activity and to reduce risk, and have also begun working with law enforcement,” said the company in a statement at the time of the attack.
Insofar, the exact number of victims has not been released, and the company says it is working diligently on an internal investigation into the incident.
The original breach was carried out by the Medusa ransomware group, a ransomware-as-a-service (RaaS) which first appeared on the scene in 2021. The threat actors asked for $8 million (£6.3m) to delete data allegedly stolen from TFS.
The company now has a 10-day window to respond to their extortion, with the option to extend the deadline for an additional $10K (£7.9K) per day
In a letter sent to impacted German users, obtained by Heise, the breach could have exposed information such as full names, postal code and address, contract details and International Bank Account Numbers (IBANs).
Recommended reading
- Toyota Restarts Driverless Vehicles After Paralympian Injured
- Immigration Exemption Found in Breach Of Data Protection Act
- Ransomware Attacks up 81% Year-on-year in October
Upon detection of the unauthorised access, Toyota shut down certain systems, which resulted in an impact on customer services. Since it likely did not engage in negotiations with the cybercriminals, the leaked data has since been made accessible on Medusa’s dark web extortion portal.
Compromised data could lead to phishing attacks, social engineering, scams, financial fraud, and identity theft for victims. Toyota has assured customers that it will update them if the investigation reveals any further data exposure.
This announcement comes on the tail end of a year which saw a record high in ransomware attacks. According to the latest NCC Group Threat Pulse report, ransomware attacks rose 81% year-on-year, and claimed over 50% more victims than last year.





