Medusa ransomware hit Toyota Financial Services in Europe and Africa

Organization
Toyota Financial Services
Exploit
Ransomware
Industry
Automotive Finance

Toyota Financial Services, the vehicle financing and leasing arm of Toyota Motor Corporation, confirmed in November 2023 that it had found unauthorized activity on systems at a limited number of its locations in Europe and Africa. The company took the affected systems offline while it investigated and said it was working with law enforcement and outside specialists.

The Medusa ransomware group claimed the attack on November 17, listing Toyota Financial Services on its leak site and demanding $8 million to delete the files it said it had taken. Medusa set a deadline of November 26 and offered to extend it for $10,000 a day.

The sample files Medusa published included financial documents, invoices, hashed account passwords and passport scans. Much of the material was in German, which pointed to systems in Germany as the source. Researcher Kevin Beaumont noted that Toyota's German office had a Citrix Gateway exposed to the internet and vulnerable to Citrix Bleed, CVE-2023-4966, which was being widely exploited at the time.

Toyota did not confirm whether data had been stolen when it first acknowledged the incident, saying only that it was bringing systems back online and regretted the inconvenience to customers and business partners. The disruption was confined to the finance subsidiary and did not affect vehicle production.

Sources