February 23, 2023
LockBit #ransomware group added Trèves Group, a supplier of acoustic and thermal solutions based in #France, to their victim list. They claim to have access to 250 GB of company data.
February 23, 2023
LockBit #ransomware group added Trèves Group, a supplier of acoustic and thermal solutions based in #France, to their victim list. They claim to have access to 250 GB of company data.
September 10, 2023
ALPS’ North American production operations and delivery was impacted by a ransomware incident on their systems. ALP promptly shut off the network connection of servers and other devices infected and reported they “are still working to restore equipment and production functions. At present, with the exception of our production bases in Mexico, we have resumed production and delivery with alternative methods for system failures.”
North American employee data was reportedly leaked.
This follows on the heels of a separate attack on July 6, 2023, where an attack exfiltrated data on 16,000 employees.
December 11, 2023
Toyota Financial Services (TFS) is warning customers it suffered a data breach, stating that sensitive personal and financial data was exposed in the attack. Earlier this month, Toyota Kreditbank GmbH in Germany admitted that hackers gained access to customers’ personal data.
German news outlet Heise received a sample of the notices sent by Toyota to German customers, informing that personal information, including leasing and bank account information has been compromised. However, the internal investigation isn’t complete yet, and Toyota promises to promptly update affected customers should the internal investigation reveal further data exposure.
February 5, 2023
Laremo GmbH was hit by ransomware attack on February 5. A company issued statement on their website states that customer database and financial accounting data were compromised.
The LockBit ransomware group claimed responsibility for the attack and uploaded the company’s data on their dark web site on February 19.
April 12, 2023
Hyundai has disclosed a data breach impacting Italian and French car owners and those who booked a test drive, warning that hackers gained access to personal data. It is unclear how many Hyundai customers this incident impacts, how long the network intrusion lasted, and what other countries might be affected.
BleepingComputer has contacted Hyundai to learn more about the security incident
December 5, 2023
Japanese automobile manufacturer Nissan announced that its Australia and New Zealand arm suffered a significant cyber security incident that affected the company’ daily operations. The company informed customers of its Nissan Oceania division of a potential data breach, warning them that there is a risk of scams in the upcoming days. The company did not share details about the attack or its scope. The problems suffered by the company suggest that its systems were infected with ransomware.
The carmaker warned that some dealer systems will be impacted despite local dealerships continue to operate.
September 15, 2022
Toyota Motor Corporation customers’ personal information may have been exposed after an access key was publicly available on GitHub for almost five years. The T-Connect site source code was mistakenly published on GitHub. The code contained an access key to the data server that stored customer email addresses and management numbers.
Toyota T-Connect is the automaker’s official connectivity app that allows owners of Toyota cars to link their smartphone with the vehicle’s infotainment system.
April 17, 2023
Toyota Motor Corporation disclosed a data breach on its cloud environment that exposed the car-location information of 2,150,000 customers for ten years, between November 6, 2013, and April 17, 2023. “It was discovered that part of the data that Toyota Motor Corporation entrusted to Toyota Connected Corporation to manage had been made public due to misconfiguration of the cloud environment,” reads the notice (machine translated). No customers are believed to be at risk of criminals tracking down a user’s car, as they would be difficult to track without knowing a target vehicle’s VIN.
This incident exposed the information of customers who used Toyota’s in-car smart service T-Connect for voice assistance, customer service support, car status and management, and on-road emergency help between January 2, 2012, and April 17, 2023.
November 15, 2023
A cyberattack that hit automotive parts production at Yanfeng International Automotive Technology in the US this week has had a knock-on effect at Stellantis, with the carmaker forced to halt assembly on certain lines.
In a short statement Stellantis said: “Due to an issue with an external supplier, production at some North America assembly plants has been disrupted. We are monitoring the situation and working with the supplier to mitigate any further impact to our operations.”
The carmaker said it would not provide information on affected plants or any other details. There has been no comment from Yanfeng.
Yangfeng manufactures key parts like seats, interiors, and electronics, among other components. Yanfeng also supplies General Motors but the carmaker has not yet said if it will have any impact on its current production schedule.
November 16, 2023
Toyota Financial Services (TFS) has confirmed that it detected unauthorized access on some of its systems in Europe and Africa after Medusa ransomware claimed an attack on the company. The Medusa ransomware gang listed TFS to its data leak site on the dark web, demanding a payment of $8,000,000 to delete data allegedly stolen from the Japanese company. The threat actors gave Toyota 10 days to respond, with the option to extend the deadline for $10,000 per day. While Toyota Finance did not confirm if data was stolen in the attack, the threat actors claim to have exfiltrated files and threatened that the data will be leaked if a ransom is not paid.