Toyota Financial Services is warning customers it suffered a data breach, stating that sensitive personal and financial data was exposed in the attack.
Toyota Financial Services, a subsidiary of Toyota Motor Corporation, is a global entity with a presence in 90% of the markets where Toyota sells its cars, providing auto financing to its customers.
Last month, the company confirmed that it detected unauthorized access on some of its systems in Europe and Africa, following a claim from Medusa ransomware about successfully compromising the Japanese automaker's division.
The threat actors demanded a payment of $8,000,000 to delete the stolen data and gave Toyota 10 days to respond to their blackmail.
At the time, a Toyota spokesperson told BleepingComputer that the company had detected unauthorized access on some of its systems in Europe and Africa.
The company took certain systems offline to contain the breach, which impacted customer services.
Presumably, Toyota has not negotiated a ransom payment with the cybercriminals, and currently, all data has been leaked on Medusa's extortion portal on the dark web.
Earlier this month, Toyota Kreditbank GmbH in Germany was identified as one of the impacted divisions, admitting that hackers gained access to customers' personal data.
This type of data can be used in phishing, social engineering, scams, financial fraud, and even identity theft attempts.
The notification verifies the above data as compromised based on the ongoing investigation.
The internal investigation isn't complete yet, and there remains a possibility that attackers accessed additional information.
Toyota promises to promptly update affected customers should the internal investigation reveal further data exposure.
BleepingComputer has contacted Toyota for additional information, like the exact number of exposed customers, but we have not heard back by publication time.
Toyota confirms breach after Medusa ransomware threatens to leak data.
Navy contractor Austal USA confirms cyberattack after data leak.
Auto parts giant AutoZone warns of MOVEit data breach.
Yamaha Motor confirms ransomware attack on Philippines subsidiary.
Kyocera AVX says ransomware attack impacted 39,000 individuals.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 11 Dec 2023 17:55:07 +0000