Automotive

Industry

Operational Impact at Electronics Company Alps Alpine Group

September 10, 2023

ALPS’ North American production operations and delivery was impacted by a ransomware incident on their systems. ALP promptly shut off the network connection of servers and other devices infected and reported they “are still working to restore equipment and production functions. At present, with the exception of our production bases in Mexico, we have resumed production and delivery with alternative methods for system failures.”

North American employee data was reportedly leaked.

This follows on the heels of a separate attack on July 6, 2023, where an attack exfiltrated data on 16,000 employees.

read more

Hackers Accessed Customer Information at Toyota Kreditbank Germany

December 11, 2023

Toyota Financial Services (TFS) is warning customers it suffered a data breach, stating that sensitive personal and financial data was exposed in the attack. Earlier this month, Toyota Kreditbank GmbH in Germany admitted that hackers gained access to customers’ personal data.

German news outlet Heise received a sample of the notices sent by Toyota to German customers, informing that personal information, including leasing and bank account information has been compromised. However, the internal investigation isn’t complete yet, and Toyota promises to promptly update affected customers should the internal investigation reveal further data exposure.

read more

Databreach at German Manufacturer Laremo GmbH

February 5, 2023

Laremo GmbH was hit by ransomware attack on February 5. A company issued statement on their website states that customer database and financial accounting data were compromised.

The LockBit ransomware group claimed responsibility for the attack and uploaded the company’s data on their dark web site on February 19.

read more

Databreach Impacts Italian and French Hyundai Car Owners

April 12, 2023

Hyundai has disclosed a data breach impacting Italian and French car owners and those who booked a test drive, warning that hackers gained access to personal data. It is unclear how many Hyundai customers this incident impacts, how long the network intrusion lasted, and what other countries might be affected.

BleepingComputer has contacted Hyundai to learn more about the security incident

read more

Cyberattack and Potentional Data Breach at Nissan Oceania

December 5, 2023

Japanese automobile manufacturer Nissan announced that its Australia and New Zealand arm suffered a significant cyber security incident that affected the company’ daily operations. The company informed customers of its Nissan Oceania division of a potential data breach, warning them that there is a risk of scams in the upcoming days. The company did not share details about the attack or its scope. The problems suffered by the company suggest that its systems were infected with ransomware.

The carmaker warned that some dealer systems will be impacted despite local dealerships continue to operate.

read more

Toyota T-Connect Source Code Exposed on Github for 5 Years

September 15, 2022

Toyota Motor Corporation customers’ personal information may have been exposed after an access key was publicly available on GitHub for almost five years. The T-Connect site source code was mistakenly published on GitHub. The code contained an access key to the data server that stored customer email addresses and management numbers.

Toyota T-Connect is the automaker’s official connectivity app that allows owners of Toyota cars to link their smartphone with the vehicle’s infotainment system.

read more

Toyota Databreach for Ten Years Exposes Car Location Data of over 2M Customers

April 17, 2023

Toyota Motor Corporation disclosed a data breach on its cloud environment that exposed the car-location information of 2,150,000 customers for ten years, between November 6, 2013, and April 17, 2023. “It was discovered that part of the data that Toyota Motor Corporation entrusted to Toyota Connected Corporation to manage had been made public due to misconfiguration of the cloud environment,” reads the notice (machine translated). No customers are believed to be at risk of criminals tracking down a user’s car, as they would be difficult to track without knowing a target vehicle’s VIN.

This incident exposed the information of customers who used Toyota’s in-car smart service T-Connect for voice assistance, customer service support, car status and management, and on-road emergency help between January 2, 2012, and April 17, 2023.

read more

Yanfeng cyberattack disrupts production at Stellantis

November 15, 2023

A cyberattack that hit automotive parts production at Yanfeng International Automotive Technology in the US this week has had a knock-on effect at Stellantis, with the carmaker forced to halt assembly on certain lines.

In a short statement Stellantis said: “Due to an issue with an external supplier, production at some North America assembly plants has been disrupted. We are monitoring the situation and working with the supplier to mitigate any further impact to our operations.”

The carmaker said it would not provide information on affected plants or any other details. There has been no comment from Yanfeng.
Yangfeng manufactures key parts like seats, interiors, and electronics, among other components. Yanfeng also supplies General Motors but the carmaker has not yet said if it will have any impact on its current production schedule.

read more

Medusa Ransomware Gang Demands $8M Ransom from Toyota

November 16, 2023

Toyota Financial Services (TFS) has confirmed that it detected unauthorized access on some of its systems in Europe and Africa after Medusa ransomware claimed an attack on the company. The Medusa ransomware gang listed TFS to its data leak site on the dark web, demanding a payment of $8,000,000 to delete data allegedly stolen from the Japanese company. The threat actors gave Toyota 10 days to respond, with the option to extend the deadline for $10,000 per day. While Toyota Finance did not confirm if data was stolen in the attack, the threat actors claim to have exfiltrated files and threatened that the data will be leaked if a ransom is not paid.

read more