Toyota confirms customer data exposed after 240 GB leak blamed on third party

Organization
Toyota
Exploit
Third-Party Data Breach
Industry
Automotive

In August 2024 a threat actor using the handle ZeroSevenGroup posted a 240 GB archive on the BreachForums cybercrime forum and said it had been taken from a United States branch of Toyota. The actor claimed the files held customer and employee records, contracts, financial documents, email chains, credentials and details of the victim's network infrastructure, and said the network had been mapped with the ADRecon tool.

Toyota confirmed that customer and employee data had been exposed. The company said the issue was limited in scope and was not a system wide issue, and that it had engaged with those affected and would provide assistance if needed. Toyota Motor North America separately said its own systems had not been breached or compromised, and that the forum post appeared to relate to a third-party entity that had been misrepresented as Toyota. The company said it was not at liberty to name that entity.

Researchers who examined the archive found that the files had been created or collected on 25 December 2022, which suggested the attackers had reached a backup server rather than live production systems. Toyota did not say how many people were affected and released no technical detail about how the data was taken.

The leak came less than a year after a separate incident at Toyota Financial Services, which was extorted by the Medusa ransomware group in late 2023. Medusa published data from that subsidiary after an $8 million demand went unpaid.

Sources