Toyota Admits Vehicle Data Leak of Two Million Users in Japan

Toyota Admits Vehicle Data Leak of Two Million Users in Japan

BY  
Seneca ESG  
- May 18, 2023

Toyota Motor disclosed that the vehicle data of 2.15 million users in Japan had been publicly available for a decade from November 2013 to mid-April 2023, due to human error, as reported by Reuters on May 12. According to the company, the leaked data may include details such as vehicle locations and identification numbers of vehicle devices. However, there have been no reports of malicious use. The affected users comprise almost the entire customer base who signed up for Toyota’s major cloud service platform, T-Connect, as well as the users of G-Link, a similar service for Lexus vehicles owners. Upon discovering the issue, Toyota has taken measures to block outside access to the data and has initiated an investigation into all cloud environments managed by Toyota Connected Corp.

Toyota admitted to lacking active detection mechanisms and processes to promptly identify public exposure of data when questioned about the delay in detecting the recent data leak. The company has commited to implementing a system to audit cloud settings, establishing a system to continuously monitor settings, and conducting comprehensive training for employees on data handling rules. Prior to this data leak incident, Toyota had already informed its customers in October 2022 of another significant data breach related to its cloud service platform. Specifically, it had inadvertently exposed a credential that provided access to the T-Connect customer database in a public GitHub repository for nearly five years, potentially compromising data for over 290,000 customers.

S****ources:

https://www.reuters.com/business/autos-transportation/toyota-flags-possible-leak-more-than-2-mln-users-vehicle-data-japan-2023-05-12/

https://www.straitstimes.com/asia/east-asia/toyota-says-more-than-2-million-face-risk-of-vehicle-data-leak-in-japan

https://www.bleepingcomputer.com/news/security/toyota-car-location-data-of-2-million-customers-exposed-for-ten-years/

https://blog.gitguardian.com/toyota-accidently-exposed-a-secret-key-publicly-on-github-for-five-years/

立即開始使用 Seneca ESG 工具包

監控投資組合 ESG 表現,自建 ESG 框架,讓商業決策更精準。

Toolkit

Seneca ESG

有興趣?立即聯絡我們

請填寫右側表單,或直接郵件聯絡我們:

sales@senecaesg.com

新加坡辦公室

7 Straits View, Marina One East Tower, #05-01, Singapore 018936

+(65) 6223 8888

巴塞隆拿辦公室

Carrer de la Tapineria, 10

Ciutat Vella, 08002, Barcelona, Spain

+34 612 22 79 06

台北辦公室

台灣台北市大安區敦化南路二段77號7樓,106414

(+886) 02 2706 2108

利馬辦公室

Av. Santo Toribio 143,

San Isidro, Lima, Peru, 15073

(+51) 951 722 377