Toyota Admits Vehicle Data Leak of Two Million Users in Japan

Toyota Admits Vehicle Data Leak of Two Million Users in Japan

BY  
Seneca ESG  
- May 18, 2023

Toyota Motor disclosed that the vehicle data of 2.15 million users in Japan had been publicly available for a decade from November 2013 to mid-April 2023, due to human error, as reported by Reuters on May 12. According to the company, the leaked data may include details such as vehicle locations and identification numbers of vehicle devices. However, there have been no reports of malicious use. The affected users comprise almost the entire customer base who signed up for Toyota’s major cloud service platform, T-Connect, as well as the users of G-Link, a similar service for Lexus vehicles owners. Upon discovering the issue, Toyota has taken measures to block outside access to the data and has initiated an investigation into all cloud environments managed by Toyota Connected Corp.

Toyota admitted to lacking active detection mechanisms and processes to promptly identify public exposure of data when questioned about the delay in detecting the recent data leak. The company has commited to implementing a system to audit cloud settings, establishing a system to continuously monitor settings, and conducting comprehensive training for employees on data handling rules. Prior to this data leak incident, Toyota had already informed its customers in October 2022 of another significant data breach related to its cloud service platform. Specifically, it had inadvertently exposed a credential that provided access to the T-Connect customer database in a public GitHub repository for nearly five years, potentially compromising data for over 290,000 customers.

S****ources:

https://www.reuters.com/business/autos-transportation/toyota-flags-possible-leak-more-than-2-mln-users-vehicle-data-japan-2023-05-12/

https://www.straitstimes.com/asia/east-asia/toyota-says-more-than-2-million-face-risk-of-vehicle-data-leak-in-japan

https://www.bleepingcomputer.com/news/security/toyota-car-location-data-of-2-million-customers-exposed-for-ten-years/

https://blog.gitguardian.com/toyota-accidently-exposed-a-secret-key-publicly-on-github-for-five-years/

Commencez à utiliser le toolkit Seneca ESG aujourd'hui

Suivez les performances ESG dans les portefeuilles, créez vos propres cadres ESG et prenez de meilleures décisions commerciales éclairées.

Toolkit

Seneca ESG

Intéressé ? Contactez-nous maintenant

Pour nous contacter, veuillez remplir le formulaire à droite ou nous envoyer directement un email à l'adresse ci-dessous

sales@senecaesg.com

Bureau de Singapour

7 Straits View, Marina One East Tower, #05-01, Singapour 018936

+(65) 6223 8888

Bureau de Barcelone

Carrer de la Tapineria, 10

Ciutat Vella, 08002, Barcelona, Spain

+34 612 22 79 06

Bureau de Taipei

77 Dunhua South Road, 7F Section 2, Da'an District Taipei City, Taïwan 106414

(+886) 02 2706 2108

Bureau de Lima

Av Jorge Basadre Grohmann 607 San Isidro, Lima, Pérou 15073

(+51) 951 722 377