Toyota Admits Vehicle Data Leak of Two Million Users in Japan

Toyota Admits Vehicle Data Leak of Two Million Users in Japan

BY  
Seneca ESG  
- May 18, 2023

Toyota Motor disclosed that the vehicle data of 2.15 million users in Japan had been publicly available for a decade from November 2013 to mid-April 2023, due to human error, as reported by Reuters on May 12. According to the company, the leaked data may include details such as vehicle locations and identification numbers of vehicle devices. However, there have been no reports of malicious use. The affected users comprise almost the entire customer base who signed up for Toyota’s major cloud service platform, T-Connect, as well as the users of G-Link, a similar service for Lexus vehicles owners. Upon discovering the issue, Toyota has taken measures to block outside access to the data and has initiated an investigation into all cloud environments managed by Toyota Connected Corp.

Toyota admitted to lacking active detection mechanisms and processes to promptly identify public exposure of data when questioned about the delay in detecting the recent data leak. The company has commited to implementing a system to audit cloud settings, establishing a system to continuously monitor settings, and conducting comprehensive training for employees on data handling rules. Prior to this data leak incident, Toyota had already informed its customers in October 2022 of another significant data breach related to its cloud service platform. Specifically, it had inadvertently exposed a credential that provided access to the T-Connect customer database in a public GitHub repository for nearly five years, potentially compromising data for over 290,000 customers.

S****ources:

https://www.reuters.com/business/autos-transportation/toyota-flags-possible-leak-more-than-2-mln-users-vehicle-data-japan-2023-05-12/

https://www.straitstimes.com/asia/east-asia/toyota-says-more-than-2-million-face-risk-of-vehicle-data-leak-in-japan

https://www.bleepingcomputer.com/news/security/toyota-car-location-data-of-2-million-customers-exposed-for-ten-years/

https://blog.gitguardian.com/toyota-accidently-exposed-a-secret-key-publicly-on-github-for-five-years/

Mulai Gunakan Seneca ESG Toolkit Hari Ini

Pantau kinerja ESG di portofolio, buat kerangka ESG Anda sendiri, dan ambil keputusan bisnis yang lebih baik.

Toolkit

Seneca ESG

Tertarik? Hubungi kami sekarang

Untuk menghubungi kami, silakan isi formulir di sebelah kanan atau email langsung ke alamat di bawah ini

sales@senecaesg.com

Kantor Singapura

7 Straits View, Marina One East Tower, #05-01, Singapura 018936

+(65) 6223 8888

Kantor Barcelona

Carrer de la Tapineria, 10

Ciutat Vella, 08002, Barcelona, Spain

+34 612 22 79 06

Kantor Taipei

77 Dunhua South Road, 7F Section 2, Distrik Da'an Taipei City, Taiwan 106414

(+886) 02 2706 2108

Kantor Lima

Av. Santo Toribio 143,

San Isidro, Lima, Peru, 15073

(+51) 951 722 377