Toyota Server Misconfiguration Leaks Owners Data for Over Seven Years

As per reports, On May 12, 2023, Toyota Motor Corporation discovered that they had been subject to a Potential data leak due to misconfiguration of the Cloud Environment on their Japanese side.

Toyota Investigated all of its cloud environments and found that some customer information was accessible externally.

Currently, there has been another incident at Toyota Motors. The company stated that this incident was also due to insufficient data dissemination and handling rules.

It was also mentioned that the company has now implemented a system for monitoring cloud configurations.

Toyota Motors confirmed that there wasn’t any secondary use of the data exfiltrated by the threat actors.

The company is currently working on resolving this issue by enforcing better rules for data handling and educating its employees.

Data Leak Incident List

1. Domestic Service Incidents In Japan

Map data updates, vehicle device IDs, and other information relating to navigation terminals were potentially accessible externally.

However, Toyota Motors stated this information alone would not be sufficient for threat actors to affect any vehicle.

Furthermore, Customers who subscribed to the G-Book with a G-Book mX or G-Book mX Pro compatible systems were subjectively impacted.

G-Link / G-Link Lite subscribers who renewed their Maps on-demand service between February 9, 2015, and March 21, 2022, are affected due to this incident.

Toyota stated that the number of impacted customers accounts for around 260,000. The cloud environments were suspected to be externally accessible over 7 years, from February 9, 2015, to May 15, 2023.

2. Overseas Service Incidents

Cloud environment for overseas dealers, which consists of files for maintenance and investigation of the system, was also externally accessible due to a misconfiguration.

These files contain the Address, Vehicle Identification Number (VIN), Email address, Phone number, Name, and Vehicle Registration Number.

After discovering this, Toyota Motors Corporation has immediately blocked external access. 

Countries that were affected due to this includes some of the Asian countries and Oceanic.

The misconfiguration and external access were discovered to be available from October 2016 to May 2023.

Vehicles that were affected due to this incident

VehiclePeriod of time it was on sale
LSOctober 2009 – September 2014
GSSeptember 2009 – August 2014
HSJuly 2009 – July 2015
ISJuly 2009 – August 2013
IS FDecember 2007 – May 2014
IS CMay 2009 – July 2014
LFADecember 2010 – December 2012
SCAugust 2009 – July 2010
CTJanuary 2011 – December 2013
RXJanuary 2009 – September 2015

Toyota Motors claimed that they have set up a customer service center to aid affected customers.

It was also mentioned that Toyota Motors will deal with the information protection laws and each country’s regulations.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir Kutleshi,…

3 hours ago

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…

2 days ago

Beware! Weaponized Job Recruitment Emails Spreading BeaverTail and Tropidoor Malware

A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…

2 days ago

EncryptHub Ransomware Uncovered Through ChatGPT Use and OPSEC Failures

EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…

2 days ago

PoisonSeed Targets CRM and Bulk Email Providers in New Supply Chain Phishing Attack

A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM) and…

2 days ago

Beware! Fake Unpaid Tolls Messages Used in Phishing Attack to Steal Login Credentials

A surge in phishing text messages claiming unpaid tolls has been linked to a massive…

2 days ago